CVE-2026-19747

9.8

Tenda · CH7, CH7G, CH10, CP3, CP3 Pro, CP7

A command injection vulnerability in the ATE Module of various Tenda devices allows unauthenticated remote attackers to execute arbitrary system commands via the CAte::HandleCmd function.

Executive summary

A critical command injection vulnerability in multiple Tenda network devices enables unauthenticated remote code execution, posing a severe risk to device integrity and network security.

Vulnerability

This is a command injection vulnerability (CWE-77) located in the CAte::HandleCmd function within the ATE Module. The vulnerability is accessible to unauthenticated remote attackers, allowing for full system compromise.

Business impact

Successful exploitation of this vulnerability grants an attacker full control over the affected Tenda device. This can lead to complete loss of confidentiality, integrity, and availability of the device, potential lateral movement into the local network, and the deployment of persistent malware. Given the CVSS score of 9.8, the risk is classified as critical, necessitating immediate attention.

Remediation

Immediate Action: Identify all instances of the affected Tenda hardware within the environment and restrict their exposure to the public internet immediately.

Proactive Monitoring: Monitor network traffic for unusual outbound connections originating from Tenda devices, which may indicate command-and-control communication.

Compensating Controls: Implement strict firewall rules to block remote access to the administrative interfaces of these devices from untrusted networks.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists via GitHub.

Analyst recommendation

This vulnerability represents a critical risk to organizational security. Administrators should prioritize isolating affected devices from the internet until official firmware updates are applied, as remote attackers can easily leverage this flaw to gain full control of the impacted hardware.

More Tenda CVEs