CVE-2026-19750
Severity CVSS v4.0:
HIGH
Type:
CWE-255
Credentials Management
Publication date:
13/08/2026
Last modified:
14/08/2026
Description
A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used.
Impact
Base Score 4.0
8.20
Severity 4.0
HIGH
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
7.60
Severity 2.0
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/howitouchyou/Tenda-Smart-Camera-Vulnerability/blob/main/Tenda%20Camera%20SSH%20Hard-coded%20Password/Tenda%20Camera%20SSH%20Hard-coded%20Password.md
- https://vuldb.com/cve/CVE-2026-19750
- https://vuldb.com/submit/868524
- https://vuldb.com/vuln/389501
- https://vuldb.com/vuln/389501/cti
- https://www.tenda.com.cn/



