CVE-2026-19750

Summary

A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used.

Affected Software

VendorProductVersion RangeStatus
TendaCHV21.*affected
TendaCHV22.*affected
TendaCHV25.*affected
TendaCHV26.*affected
TendaCHV27.*affected
TendaCPV21.*affected
TendaCPV22.*affected
TendaCPV25.*affected
TendaCPV26.*affected
TendaCPV27.*affected
TendaTX3V21.*affected
TendaTX3V22.*affected
TendaTX3V25.*affected
TendaTX3V26.*affected
TendaTX3V27.*affected

Weaknesses

  • CWE-259: Use of Hard-coded Password
  • CWE-255: Credentials Management

References