3.7

CVE-2026-19749

Tenda CH7 RTSP/ONVIF missing authentication

A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTenda
Produkt CH7
Version 20260625
Status affected
HerstellerTenda
Produkt CH7G
Version 20260625
Status affected
HerstellerTenda
Produkt CH10
Version 20260625
Status affected
HerstellerTenda
Produkt CP3
Version 20260625
Status affected
HerstellerTenda
Produkt CP3 Pro
Version 20260625
Status affected
HerstellerTenda
Produkt CP7
Version 20260625
Status affected
HerstellerTenda
Produkt TC3B14C
Version 20260625
Status affected
HerstellerTenda
Produkt TC3B15C
Version 20260625
Status affected
HerstellerTenda
Produkt TC3T14C
Version 20260625
Status affected
HerstellerTenda
Produkt TC3T15C
Version 20260625
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.333
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@vuldb.com 2.9 0 0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
cna@vuldb.com 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

https://www.tenda.com.cn/
https://vuldb.com/vuln/389500
https://vuldb.com/vuln/389500/cti
https://vuldb.com/cve/CVE-2026-19749
https://vuldb.com/submit/868503
https://github.com/howitouchyou/Tenda-Smart-Camera-Vulnerability/blob/main/Tenda%20RTSP_ONVIF%20Auth%20Bypass/Tenda%20RTSP_ONVIF%20Auth%20Bypass.md