CVE-2026-51606
An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate
CVSS
7.5
Alto
EPSS
0.3%
p25
KEV
—
Exploit Today
7
0-100
Publicado: 9 jul 2026 · Última mod.: 10 jul 2026 · CWE-20
0.3%EPSS · 30 días0.3%
2026-07-102026-07-21
An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning any RFC 2326-compliant error response. This behavior affects the request-line URL field and header field values across multiple RTSP request types.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-16422——
——0Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)14hCVE-2026-16415——
——0Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)14hCVE-2026-16414——
——0Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)14hCVE-2026-648778.4 ALT—
——0An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.17hCVE-2026-15792——
——0A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.19hCVE-2026-157248.7 ALT—
——0In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.19h