Impact
A hard‑coded cryptographic key was discovered in the firmware of Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6. This flaw means the device stores a secret value in the code rather than generating one at runtime or securely retrieving it, directly weakening the confidentiality guarantees of the system. The likely impact is that if an attacker can obtain the key, they could decrypt administrative traffic, tamper with stored video data, or forge messages to the device. The weakened state is a classic cryptographic key storage weakness.
Affected Systems
The vulnerability applies only to Tenda Technology Co., Ltd NVR_4H CH3, version 2.1 V27.5.58.6. No other product versions or vendors are listed as affected.
Risk and Exploitability
The CVSS score is 7.5, indicating high severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, which limits publicly known exploitation information. Based on the description, it is inferred that an attacker who gains any code‑execution, debugger, or firmware‑dumping capability could retrieve the key local or remote access that allows code inspection or firmware extraction; there is no evidence of a publicly known exploit yet. Based on the pattern, the risk might remain moderate to high if such access is achieved, but precise quantification is challenging.
OpenCVE Enrichment