github.comexploit
https://github.com/howitouchyou/Tenda-Smart-Camera-Vulnerability/blob/main/Tenda%20Camera%20SSH%20Hard-coded%20Password/Tenda%20Camera%20SSH%20Hard-coded%20Password.md CVE-2026-19750
CRITICAL
Tenda CH/CP/TX3 SSH hard-coded password
Record summary
CVE-2026-19750 has a selected CVSS score of 9.2 (critical).
Description
A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used.
Description source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | V21.* | affected | |
| V22.* | affected | ||
| V25.* | affected | ||
| V26.* | affected | ||
| V27.* | affected | ||
| CVE List | V21.* | affected | |
| V22.* | affected | ||
| V25.* | affected | ||
| V26.* | affected | ||
| V27.* | affected | ||
| CVE List | V21.* | affected | |
| V22.* | affected | ||
| V25.* | affected | ||
| V26.* | affected | ||
| V27.* | affected |
References
7nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-19750 CVE-2026-19750 | CVE Analysis and ReportThird-party advisory
https://vuldb.com/cve/CVE-2026-19750 Submit #868524 | Tenda Tenda Multiple IP Cameras Multiple Versions Hard-coded CredentialsThird-party advisory
https://vuldb.com/submit/868524 VDB-389501 | Tenda CH/CP/TX3 SSH hard-coded passwordvdb entry
https://vuldb.com/vuln/389501 VDB-389501 | CTI Indicators (IOB, IOC, TTP)signaturepermissions required
https://vuldb.com/vuln/389501/cti tenda.com.cnproduct
https://www.tenda.com.cn/