CVE-2026-19747 PUBLISHED

Tenda CH7 ATE Module Kylin HandleCmd command injection

Assigner: VulDB
Reserved: 13.08.2026 Published: 13.08.2026 Updated: 14.08.2026

A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 9.3

Product Status

Vendor Tenda
Product CH7
Versions
  • Version 20260625 is affected
Vendor Tenda
Product CH7G
Versions
  • Version 20260625 is affected
Vendor Tenda
Product CH10
Versions
  • Version 20260625 is affected
Vendor Tenda
Product CP3
Versions
  • Version 20260625 is affected
Vendor Tenda
Product CP3 Pro
Versions
  • Version 20260625 is affected
Vendor Tenda
Product CP7
Versions
  • Version 20260625 is affected
Vendor Tenda
Product TC3B14C
Versions
  • Version 20260625 is affected
Vendor Tenda
Product TC3B15C
Versions
  • Version 20260625 is affected
Vendor Tenda
Product TC3T14C
Versions
  • Version 20260625 is affected
Vendor Tenda
Product TC3T15C
Versions
  • Version 20260625 is affected

Credits

  • Howitouchyou (VulDB User) reporter

References

Problem Types

  • Command Injection CWE
  • Injection CWE