Tenda CH7是中国Tenda公司的一款路由器。 Tenda CH7、CH7G、CH10、CP3、CP3 Pro、CP7、TC3B14C、TC3B15C、TC3T14C和TC3T15C 20260625及之前版本存在安全漏洞,该漏洞源于ATE Module组件Kylin文件中的CAte::HandleCmd函数存在命令注入漏洞,可能导致远程攻击者执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Tenda | CH10 | 20260625 |
affected |
| Tenda | CH7 | 20260625 |
affected |
| Tenda | CH7G | 20260625 |
affected |
| Tenda | CP3 | 20260625 |
affected |
| Tenda | CP3 Pro | 20260625 |
affected |
| Tenda | CP7 | 20260625 |
affected |
| Tenda | TC3B14C | 20260625 |
affected |
| Tenda | TC3B15C | 20260625 |
affected |
| Tenda | TC3T14C | 20260625 |
affected |
| Tenda | TC3T15C | 20260625 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Tenda | CH7 | 20260625 |
cpe:2.3:h:tenda:ch7:*:*:*:*:*:*:*:*
|
|
| Tenda | CH7G | 20260625 |
cpe:2.3:h:tenda:ch7g:*:*:*:*:*:*:*:*
|
|
| Tenda | CH10 | 20260625 |
cpe:2.3:h:tenda:ch10:*:*:*:*:*:*:*:*
|
|
| Tenda | CP3 | 20260625 |
cpe:2.3:h:tenda:cp3:*:*:*:*:*:*:*:*
|
|
| Tenda | CP3 Pro | 20260625 |
cpe:2.3:h:tenda:cp3_pro:*:*:*:*:*:*:*:*
|
|
| Tenda | CP7 | 20260625 |
cpe:2.3:h:tenda:cp7:*:*:*:*:*:*:*:*
|
|
| Tenda | TC3B14C | 20260625 |
cpe:2.3:h:tenda:tc3b14c:*:*:*:*:*:*:*:*
|
|
| Tenda | TC3B15C | 20260625 |
cpe:2.3:h:tenda:tc3b15c:*:*:*:*:*:*:*:*
|
|
| Tenda | TC3T14C | 20260625 |
cpe:2.3:h:tenda:tc3t14c:*:*:*:*:*:*:*:*
|
|
| Tenda | TC3T15C | 20260625 |
cpe:2.3:h:tenda:tc3t15c:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-19750 | 8.1 HIGH | Tenda CH/CP/TX3 SSH hard-coded password |
| CVE-2026-19748 | 3.7 LOW | Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy |
| CVE-2026-19749 | 3.7 LOW | Tenda CH7 RTSP/ONVIF missing authentication |
No comments yet