PT-2026-71869 · Tenda · Ch10+9
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Tenda CH7 versions prior to 20260625
Tenda CH7G versions prior to 20260625
Tenda CH10 versions prior to 20260625
Tenda CP3 versions prior to 20260625
Tenda CP3 Pro versions prior to 20260625
Tenda CP7 versions prior to 20260625
Tenda TC3B14C versions prior to 20260625
Tenda TC3B15C versions prior to 20260625
Tenda TC3T14C versions prior to 20260625
Tenda TC3T15C versions prior to 20260625
Description
A flaw in the RTSP/ONVIF component allows remote attackers to bypass authentication through specific manipulation. RTSP (Real Time Streaming Protocol) is a network control protocol designed for the use of efficient delivery of real-time media streams, and ONVIF (Open Network Video Interface Forum) is a global standard for the integration of IP-based physical security products.
Recommendations
Update Tenda CH7 to a version released after 20260625.
Update Tenda CH7G to a version released after 20260625.
Update Tenda CH10 to a version released after 20260625.
Update Tenda CP3 to a version released after 20260625.
Update Tenda CP3 Pro to a version released after 20260625.
Update Tenda CP7 to a version released after 20260625.
Update Tenda TC3B14C to a version released after 20260625.
Update Tenda TC3B15C to a version released after 20260625.
Update Tenda TC3T14C to a version released after 20260625.
Update Tenda TC3T15C to a version released after 20260625.
As a temporary mitigation, restrict access to the RTSP/ONVIF component.
Exploit
Fix
Improper Authentication
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ch10
Ch7
Ch7G
Cp3
Cp3 Pro
Cp7
Tc3B14C
Tc3B15C
Tc3T14C
Tc3T15C