Tenda CH是中国Tenda公司的一款路由交换设备。 Tenda CH、Tenda CP和Tenda TX3 V21.x版本、V22.x版本、V25.x版本、V26.x版本和V27.x版本存在信任管理问题漏洞,该漏洞源于SSH组件存在硬编码密码,可能导致远程攻击者利用该密码进行未授权访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-19747 | 9.8 CRITICAL | Tenda CH7 ATE Module Kylin HandleCmd command injection |
| CVE-2026-19748 | 3.7 LOW | Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy |
| CVE-2026-19749 | 3.7 LOW | Tenda CH7 RTSP/ONVIF missing authentication |
No comments yet