3.7
CVE-2026-19749
- EPSS 0.4%
- Veröffentlicht 13.08.2026 20:45:09
- Zuletzt bearbeitet 18.08.2026 02:17:25
- CVE-Watchlists
- Unerledigt
Tenda CH7 RTSP/ONVIF missing authentication
A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTenda
≫
Produkt
CH7
Version
20260625
Status
affected
HerstellerTenda
≫
Produkt
CH7G
Version
20260625
Status
affected
HerstellerTenda
≫
Produkt
CH10
Version
20260625
Status
affected
HerstellerTenda
≫
Produkt
CP3
Version
20260625
Status
affected
HerstellerTenda
≫
Produkt
CP3 Pro
Version
20260625
Status
affected
HerstellerTenda
≫
Produkt
CP7
Version
20260625
Status
affected
HerstellerTenda
≫
Produkt
TC3B14C
Version
20260625
Status
affected
HerstellerTenda
≫
Produkt
TC3B15C
Version
20260625
Status
affected
HerstellerTenda
≫
Produkt
TC3T14C
Version
20260625
Status
affected
HerstellerTenda
≫
Produkt
TC3T15C
Version
20260625
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.333 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@vuldb.com | 2.9 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| cna@vuldb.com | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| cna@vuldb.com | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:P/I:N/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
https://www.tenda.com.cn/
https://vuldb.com/vuln/389500
https://vuldb.com/vuln/389500/cti
https://vuldb.com/cve/CVE-2026-19749
https://vuldb.com/submit/868503
https://github.com/howitouchyou/Tenda-Smart-Camera-Vulnerability/blob/main/Tenda%20RTSP_ONVIF%20Auth%20Bypass/Tenda%20RTSP_ONVIF%20Auth%20Bypass.md