CVE-2026-19747
Severity CVSS v4.0:
HIGH
Type:
CWE-74
Injection
Publication date:
13/08/2026
Last modified:
14/08/2026
Description
A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely.
Impact
Base Score 4.0
8.90
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/howitouchyou/Tenda-Smart-Camera-Vulnerability/blob/main/Tenda%20Command%20Injection/Tenda%20Command%20Injection.md
- https://vuldb.com/cve/CVE-2026-19747
- https://vuldb.com/submit/868463
- https://vuldb.com/vuln/389498
- https://vuldb.com/vuln/389498/cti
- https://www.tenda.com.cn/
- https://github.com/howitouchyou/Tenda-Smart-Camera-Vulnerability/blob/main/Tenda%20Command%20Injection/Tenda%20Command%20Injection.md



