Description
A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to insufficient entropy. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult.
Published: 2026-08-13
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to insufficient entropy. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult.
Title Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy
First Time appeared Tenda
Tenda ch10
Tenda ch7
Tenda ch7g
Tenda cp3
Tenda cp3 Pro
Tenda cp7
Tenda tc3b14c
Tenda tc3b15c
Tenda tc3t14c
Tenda tc3t15c
Weaknesses CWE-330
CWE-331
CPEs cpe:2.3:h:tenda:ch10:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ch7:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ch7g:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:cp3:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:cp3_pro:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:cp7:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tc3b14c:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tc3b15c:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tc3t14c:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tc3t15c:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda ch10
Tenda ch7
Tenda ch7g
Tenda cp3
Tenda cp3 Pro
Tenda cp7
Tenda tc3b14c
Tenda tc3b15c
Tenda tc3t14c
Tenda tc3t15c
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-14T16:44:13.929Z

Reserved: 2026-08-13T14:39:32.611Z

Link: CVE-2026-19748

cve-icon Vulnrichment

Updated: 2026-08-14T16:44:09.395Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T21:17:46.343

Modified: 2026-08-14T19:09:39.140

Link: CVE-2026-19748

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:14:40Z

Weaknesses