LiveActive security incident?Get immediate response
CVE Record

CVE-2026-19750: Tenda CH/CP/TX3 SSH hard-coded password

A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used.

CriticalCVSS 9.2Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

Affected Tenda CH, CP, and TX3 cameras contain a hard-coded SSH password that could let a remote attacker gain powerful device access. Successful compromise could expose camera data, alter device operation, or make the device unavailable. Exploitation is rated difficult, but public exploit information increases risk.

Executive priority

Treat internet-reachable affected cameras as an immediate containment priority. Restrict SSH access, identify all affected assets, and seek vendor remediation guidance. Internally isolated devices warrant prompt review because public exploit information exists, but current sources do not confirm active exploitation or provide a fixed version.

Technical view

CVE-2026-19750 affects SSH functionality in Tenda CH, CP, and TX3 devices running listed V21, V22, V25, V26, or V27 releases. It is classified under hard-coded credentials weaknesses CWE-255 and CWE-259. CVSS 4.0 is 9.2, reflecting remote, unauthenticated access with high complexity and potentially high confidentiality, integrity, and availability impact.

Likely exposure

Highest exposure exists where an affected camera's SSH service is reachable from the internet or another untrusted network. Internally reachable devices remain exposed to attackers who already have network access. The sources do not identify exact model variants, default network configuration, SSH port, or whether every firmware build within each listed release family is vulnerable.

Exploitation context

A public exploit has been published, and the CVSS vector marks exploit maturity as proof-of-concept. However, the source bundle reports that exploitation is difficult and requires high attack complexity. The CVE is not listed in CISA KEV, and the supplied evidence does not establish active exploitation.

Researcher notes

The record describes unknown affected SSH functionality and does not disclose the credential, authentication path, firmware-level root cause, or vendor fix. Product naming is broad, with wildcard CPEs and release-family version ranges. Public exploit availability supports elevated concern, but claims of widespread or active exploitation would exceed the supplied evidence.

Mitigation direction

  • Inventory Tenda CH, CP, and TX3 devices and record their exact firmware versions.
  • Block untrusted network access to device SSH services using firewall rules or access controls.
  • Segment affected cameras from business-critical systems and restrict administrative access to trusted management networks.
  • Check Tenda guidance for fixed firmware or vendor-approved mitigation; no patch is identified in the supplied sources.
  • Do not assume changing normal administrator passwords removes the separate hard-coded SSH credential.

Validation and detection

  • Confirm each device model and firmware against the listed V21, V22, V25, V26, and V27 families.
  • Test from untrusted network segments whether the device's SSH service is reachable, without attempting authentication.
  • Review device and network logs for unexpected SSH connections, authentication events, or configuration changes.
  • After remediation, verify SSH is inaccessible from untrusted networks and confirm the installed firmware version.
  • Monitor Tenda and the CVE record for clarified affected builds and remediation guidance.
Prepared
Confidence
medium
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-255: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cwe · low confidence lookup

CWE-259: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-19750 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.2 (4.0)
Known Exploited
No
Published

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

4CVSS vectors
6Timeline events
1ADP providers
7Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: noTechnical Impact: total

CVSS vector scores

4 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.2CVSS 4.0CriticalCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:PVulDB
8.1CVSS 3.1HighCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:R2.25.9VulDB
8.1CVSS 3.0HighCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:R2.25.9VulDB
7.6CVSS 2.0HighAV:N/AC:H/Au:N/C:C/I:C/A:C/E:POC/RL:W/RC:UR4.910VulDB

Vulnerability scoring details

Base CVSS 4.0 score

9.2Critical
CVSS 4.0 vector shape for CVE-2026-19750Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. Source timelineVulDB

    Advisory disclosed

  2. Source timelineVulDB

    VulDB entry created

  3. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  4. Source timelineVulDB

    VulDB entry last update

  5. CVE publishedCVE Program

    The CVE record was published.

  6. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
TendaCHV21.*, V22.*, V25.*, V26.*, V27.*Listed
TendaCPV21.*, V22.*, V25.*, V26.*, V27.*Listed
TendaTX3V21.*, V22.*, V25.*, V26.*, V27.*Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.