Description
A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to insufficient entropy. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult.
Published: 2026-08-13
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the CWebSessionManager_ParseSession function of the Kylin Web Service on Tenda devices. An attacker can manipulate the SESSION argument, causing insufficient entropy during parsing. This manipulation can enable an attacker to forge or hijack session identifiers, potentially bypassing authentication and gaining unauthorized access. The flaw leads to a compromise of confidentiality and integrity of user sessions, but does not directly affect system stability or execution. It is a weakness in session management, classified as CWE‑330 and CWE‑331.

Affected Systems

Vulnerable devices include Tenda CH10, CH7, CH7G, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C, and TC3T15C with firmware versions up to 20260625. The issue affects the Kylin Web Service component present in those product lines.

Risk and Exploitability

The CVSS score of 6.3 indicates a medium severity. The EPSS score is not available, so the exploitation probability cannot be quantified, yet the description states the attacks are highly complex and difficult to perform. The exploit can be carried out from a remote host, implying the attack vector is network-based. As the vulnerability is not listed in CISA's KEV catalog, there are currently no known deployed exploits, but the risk remains due to the potential to bypass session authentication.

Generated by OpenCVE AI on August 13, 2026 at 21:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Tenda firmware to the latest release that contains the fix for the CWebSessionManager parsing entropy issue.
  • Restrict external access to the Kylin Web Service by configuring firewall rules or network segmentation so only trusted internal hosts can reach it.
  • Continuously monitor authentication logs on affected devices for suspicious session activity and apply additional security controls such as VPN or two‑factor authentication where possible.

Generated by OpenCVE AI on August 13, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to insufficient entropy. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult.
Title Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy
First Time appeared Tenda
Tenda ch10
Tenda ch7
Tenda ch7g
Tenda cp3
Tenda cp3 Pro
Tenda cp7
Tenda tc3b14c
Tenda tc3b15c
Tenda tc3t14c
Tenda tc3t15c
Weaknesses CWE-330
CWE-331
CPEs cpe:2.3:h:tenda:ch10:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ch7:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ch7g:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:cp3:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:cp3_pro:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:cp7:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tc3b14c:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tc3b15c:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tc3t14c:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tc3t15c:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda ch10
Tenda ch7
Tenda ch7g
Tenda cp3
Tenda cp3 Pro
Tenda cp7
Tenda tc3b14c
Tenda tc3b15c
Tenda tc3t14c
Tenda tc3t15c
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-13T20:15:10.451Z

Reserved: 2026-08-13T14:39:32.611Z

Link: CVE-2026-19748

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:46.343

Modified: 2026-08-13T21:17:46.343

Link: CVE-2026-19748

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:00:05Z

Weaknesses
  • CWE-330

    Use of Insufficiently Random Values

  • CWE-331

    Insufficient Entropy