Impact
A flaw in Tenda CH, CP and TX3 firmware versions V21.x-V27.x hard‑codes an SSH password in the device’s configuration. This allows an attacker who can reach the SSH service over the network to log in with a privileged account, potentially enabling arbitrary command execution and full device compromise. The weakness is classified as CWE‑255 (Hard‑coded Credential) and CWE‑259 (Weak Password), indicating that the device relies on a static credential that is easily discoverable.
Affected Systems
The vulnerability affects Tenda CH, CP, and TX3 devices running firmware V21.x, V22.x, V25.x, V26.x, or V27.x. These include the corresponding consumer routers and smart camera models listed by the vendor. No other Tenda hardware or firmware revisions are identified as affected.
Risk and Exploitability
The CVSS score of 9.2 places the issue in the critical range. No EPSS data is currently available, and the flaw is not listed in the CISA KEV catalog. The attack vector is remote, requiring only the ability to reach the SSH port. Exploitation is reportedly difficult, but the publishment of the exploit demonstrates that an attacker can, with the necessary effort, retrieve the hard‑coded credentials and gain remote administrative access. The combined high severity and ease of network access mean that the risk to operational infrastructure is significant and should be addressed promptly.
OpenCVE Enrichment