PT-2026-71830 · Tenda · Cp7+9

·

CVE-2026-19747

·

Published

2026-08-13

·

Updated

2026-08-14

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda CH7 versions prior to 20260625 Tenda CH7G versions prior to 20260625 Tenda CH10 versions prior to 20260625 Tenda CP3 versions prior to 20260625 Tenda CP3 Pro versions prior to 20260625 Tenda CP7 versions prior to 20260625 Tenda TC3B14C versions prior to 20260625 Tenda TC3B15C versions prior to 20260625 Tenda TC3T14C versions prior to 20260625 Tenda TC3T15C versions prior to 20260625
Description A remote command injection flaw exists within the ATE Module. The issue resides in the CAte::HandleCmd() function located in the Kylin file, allowing a remote attacker to execute arbitrary commands.
Recommendations Update Tenda CH7 to a version released after 20260625. Update Tenda CH7G to a version released after 20260625. Update Tenda CH10 to a version released after 20260625. Update Tenda CP3 to a version released after 20260625. Update Tenda CP3 Pro to a version released after 20260625. Update Tenda CP7 to a version released after 20260625. Update Tenda TC3B14C to a version released after 20260625. Update Tenda TC3B15C to a version released after 20260625. Update Tenda TC3T14C to a version released after 20260625. Update Tenda TC3T15C to a version released after 20260625.

Exploit

Fix

Special Elements Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19747

Affected Products

Ch10
Ch7
Ch7G
Cp3
Cp3 Pro
Cp7
Tc3B14C
Tc3B15C
Tc3T14C
Tc3T15C