Description
A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used.
Published: 2026-08-13
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Tenda CH, CP and TX3 firmware versions V21.x-V27.x hard‑codes an SSH password in the device’s configuration. This allows an attacker who can reach the SSH service over the network to log in with a privileged account, potentially enabling arbitrary command execution and full device compromise. The weakness is classified as CWE‑255 (Hard‑coded Credential) and CWE‑259 (Weak Password), indicating that the device relies on a static credential that is easily discoverable.

Affected Systems

The vulnerability affects Tenda CH, CP, and TX3 devices running firmware V21.x, V22.x, V25.x, V26.x, or V27.x. These include the corresponding consumer routers and smart camera models listed by the vendor. No other Tenda hardware or firmware revisions are identified as affected.

Risk and Exploitability

The CVSS score of 9.2 places the issue in the critical range. No EPSS data is currently available, and the flaw is not listed in the CISA KEV catalog. The attack vector is remote, requiring only the ability to reach the SSH port. Exploitation is reportedly difficult, but the publishment of the exploit demonstrates that an attacker can, with the necessary effort, retrieve the hard‑coded credentials and gain remote administrative access. The combined high severity and ease of network access mean that the risk to operational infrastructure is significant and should be addressed promptly.

Generated by OpenCVE AI on August 13, 2026 at 22:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to a version that removes the hard‑coded SSH password.
  • Disable or block the SSH port on the device or at the network perimeter when it is not required for remote management.
  • Change the default or hard‑coded credentials to a strong, unique password and enforce password policies on all devices.

Generated by OpenCVE AI on August 13, 2026 at 22:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used.
Title Tenda CH/CP/TX3 SSH hard-coded password
First Time appeared Tenda
Tenda ch
Tenda cp
Tenda tx3
Weaknesses CWE-255
CWE-259
CPEs cpe:2.3:h:tenda:ch:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:cp:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tx3:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda ch
Tenda cp
Tenda tx3
References
Metrics cvssV2_0

{'score': 7.6, 'vector': 'AV:N/AC:H/Au:N/C:C/I:C/A:C/E:POC/RL:W/RC:UR'}

cvssV3_0

{'score': 8.1, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:R'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:R'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-13T21:30:09.762Z

Reserved: 2026-08-13T14:39:41.129Z

Link: CVE-2026-19750

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T22:17:19.290

Modified: 2026-08-13T22:17:19.290

Link: CVE-2026-19750

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:45:03Z

Weaknesses