Description
Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential compromise of cryptographic confidentiality due to a hard‑coded key
Action: Immediate Fix
AI Analysis

Impact

A hard‑coded cryptographic key was discovered in the firmware of Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6. This flaw means the device stores a secret value in the code rather than generating one at runtime or securely retrieving it, directly weakening the confidentiality guarantees of the system. The likely impact is that if an attacker can obtain the key, they could decrypt administrative traffic, tamper with stored video data, or forge messages to the device. The weakened state is a classic cryptographic key storage weakness.

Affected Systems

The vulnerability applies only to Tenda Technology Co., Ltd NVR_4H CH3, version 2.1 V27.5.58.6. No other product versions or vendors are listed as affected.

Risk and Exploitability

The CVSS score is 7.5, indicating high severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, which limits publicly known exploitation information. Based on the description, it is inferred that an attacker who gains any code‑execution, debugger, or firmware‑dumping capability could retrieve the key local or remote access that allows code inspection or firmware extraction; there is no evidence of a publicly known exploit yet. Based on the pattern, the risk might remain moderate to high if such access is achieved, but precise quantification is challenging.

Generated by OpenCVE AI on September 22, 2026 at 21:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy a firmware update that removes the hard‑coded key and implements secure key management
  • Ensure the device runs behind a firewall and is not directly exposed to the Internet, limiting potential attackers
  • Configure secure administrative access controls, including strong passwords, two‑factor authentication if available, and restrict management interfaces to trusted IP ranges

Generated by OpenCVE AI on September 22, 2026 at 21:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Hard‑coded Key Vulnerability in Tenda NVR Firmware
Weaknesses CWE-266
CWE-330

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-321
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sun, 20 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Hard‑coded Key Vulnerability in Tenda NVR Firmware
Weaknesses CWE-266
CWE-330

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Hard‑coded Cryptographic Key in Tenda NVR_4H CH3 Firmware
Weaknesses CWE-256
CWE-259

Wed, 16 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Hard‑coded Cryptographic Key in Tenda NVR_4H CH3 Firmware
Weaknesses CWE-256
CWE-259

Tue, 15 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T15:30:46.706Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79551

cve-icon Vulnrichment

Updated: 2026-09-22T15:30:36.787Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:22.073

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-79551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:45:06Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key