Impact
The vulnerability resides in the CWebSessionManager_ParseSession function of the Kylin Web Service on Tenda devices. An attacker can manipulate the SESSION argument, causing insufficient entropy during parsing. This manipulation can enable an attacker to forge or hijack session identifiers, potentially bypassing authentication and gaining unauthorized access. The flaw leads to a compromise of confidentiality and integrity of user sessions, but does not directly affect system stability or execution. It is a weakness in session management, classified as CWE‑330 and CWE‑331.
Affected Systems
Vulnerable devices include Tenda CH10, CH7, CH7G, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C, and TC3T15C with firmware versions up to 20260625. The issue affects the Kylin Web Service component present in those product lines.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium severity. The EPSS score is not available, so the exploitation probability cannot be quantified, yet the description states the attacks are highly complex and difficult to perform. The exploit can be carried out from a remote host, implying the attack vector is network-based. As the vulnerability is not listed in CISA's KEV catalog, there are currently no known deployed exploits, but the risk remains due to the potential to bypass session authentication.
OpenCVE Enrichment