Description
A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used.
Published: 2026-08-13
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication bypass flaw exists in the RTSP/ONVIF component of several Tenda camera models, allowing a remote attacker to manipulate the component without providing credentials. The vulnerability can be exploited by sending specially crafted requests, leading to unauthorized viewing or control of the camera feed. The impact is failure to authenticate, resulting in exposure of camera streams to unauthenticated users and potential privacy violations.

Affected Systems

The affected devices include Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C, and TC3T15C running firmware versions up through 20260625. Any installation of these models that have not received an updated version with proper authentication enforcement is vulnerable.

Risk and Exploitability

The CVSS score of 6.3 classifies the flaw as medium severity; the scan score is not available, and the vulnerability is not listed in the CISA KEV catalog. The description states the attack can be performed remotely with high complexity but is difficult to exploit, and a public exploit is available. Inferred from the statements, the likely attack vector is a network-based request to the RTSP/ONVIF interface, suggesting that devices exposed to the internet or untrusted internal networks are at risk. With no official CNA workaround listed, the probability of exploitation remains unknown until a security update is released.

Generated by OpenCVE AI on August 13, 2026 at 22:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest version that includes proper authentication enforcement for RTSP/ONVIF.
  • If a patch is unavailable, disable the RTSP/ONVIF service or block incoming connections to it from untrusted IP addresses using firewall rules.
  • Implement network segmentation so that camera devices are isolated from devices that do not require streaming access, and regularly monitor logs for unauthorized access attempts.

Generated by OpenCVE AI on August 13, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used.
Title Tenda CH7 RTSP/ONVIF missing authentication
First Time appeared Tenda
Tenda ch10
Tenda ch7
Tenda ch7g
Tenda cp3
Tenda cp3 Pro
Tenda cp7
Tenda tc3b14c
Tenda tc3b15c
Tenda tc3t14c
Tenda tc3t15c
Weaknesses CWE-287
CWE-306
CPEs cpe:2.3:h:tenda:ch10:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ch7:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ch7g:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:cp3:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:cp3_pro:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:cp7:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tc3b14c:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tc3b15c:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tc3t14c:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tc3t15c:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda ch10
Tenda ch7
Tenda ch7g
Tenda cp3
Tenda cp3 Pro
Tenda cp7
Tenda tc3b14c
Tenda tc3b15c
Tenda tc3t14c
Tenda tc3t15c
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:W/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-18T01:38:04.851Z

Reserved: 2026-08-13T14:39:36.955Z

Link: CVE-2026-19749

cve-icon Vulnrichment

Updated: 2026-08-18T01:37:57.990Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T21:17:46.557

Modified: 2026-08-18T02:17:25.340

Link: CVE-2026-19749

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:45:03Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function