Impact
An authentication bypass flaw exists in the RTSP/ONVIF component of several Tenda camera models, allowing a remote attacker to manipulate the component without providing credentials. The vulnerability can be exploited by sending specially crafted requests, leading to unauthorized viewing or control of the camera feed. The impact is failure to authenticate, resulting in exposure of camera streams to unauthenticated users and potential privacy violations.
Affected Systems
The affected devices include Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C, and TC3T15C running firmware versions up through 20260625. Any installation of these models that have not received an updated version with proper authentication enforcement is vulnerable.
Risk and Exploitability
The CVSS score of 6.3 classifies the flaw as medium severity; the scan score is not available, and the vulnerability is not listed in the CISA KEV catalog. The description states the attack can be performed remotely with high complexity but is difficult to exploit, and a public exploit is available. Inferred from the statements, the likely attack vector is a network-based request to the RTSP/ONVIF interface, suggesting that devices exposed to the internet or untrusted internal networks are at risk. With no official CNA workaround listed, the probability of exploitation remains unknown until a security update is released.
OpenCVE Enrichment