PT-2026-71830 · Tenda · Cp7+9
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tenda CH7 versions prior to 20260625
Tenda CH7G versions prior to 20260625
Tenda CH10 versions prior to 20260625
Tenda CP3 versions prior to 20260625
Tenda CP3 Pro versions prior to 20260625
Tenda CP7 versions prior to 20260625
Tenda TC3B14C versions prior to 20260625
Tenda TC3B15C versions prior to 20260625
Tenda TC3T14C versions prior to 20260625
Tenda TC3T15C versions prior to 20260625
Description
A remote command injection flaw exists within the ATE Module. The issue resides in the
CAte::HandleCmd() function located in the Kylin file, allowing a remote attacker to execute arbitrary commands.Recommendations
Update Tenda CH7 to a version released after 20260625.
Update Tenda CH7G to a version released after 20260625.
Update Tenda CH10 to a version released after 20260625.
Update Tenda CP3 to a version released after 20260625.
Update Tenda CP3 Pro to a version released after 20260625.
Update Tenda CP7 to a version released after 20260625.
Update Tenda TC3B14C to a version released after 20260625.
Update Tenda TC3B15C to a version released after 20260625.
Update Tenda TC3T14C to a version released after 20260625.
Update Tenda TC3T15C to a version released after 20260625.
Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ch10
Ch7
Ch7G
Cp3
Cp3 Pro
Cp7
Tc3B14C
Tc3B15C
Tc3T14C
Tc3T15C