Vulnerabilities > Tenda > CP3 Firmware > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-05-10 CVE-2023-30354 Cleartext Transmission of Sensitive Information vulnerability in Tenda CP3 Firmware 11.10.00.2211041355
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.
network
low complexity
tenda CWE-319
critical
9.8
2023-05-10 CVE-2023-30353 Command Injection vulnerability in Tenda CP3 Firmware 11.10.00.2211041355
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.
network
low complexity
tenda CWE-77
critical
9.8
2023-05-10 CVE-2023-30352 Use of Hard-coded Credentials vulnerability in Tenda CP3 Firmware 11.10.00.2211041355
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.
network
low complexity
tenda CWE-798
critical
9.8
2023-02-27 CVE-2023-23080 Command Injection vulnerability in Tenda products
Certain Tenda products are vulnerable to command injection.
network
low complexity
tenda CWE-77
critical
9.8