CVE-2026-19747: Tenda CH10

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely.

Affected products

  • Tenda CH10: version 20260625 only
  • Tenda CH7: version 20260625 only
  • Tenda CH7G: version 20260625 only
  • Tenda CP3: version 20260625 only
  • Tenda CP3 Pro: version 20260625 only
  • Tenda CP7: version 20260625 only
  • Tenda TC3B14C: version 20260625 only
  • Tenda TC3B15C: version 20260625 only
  • Tenda TC3T14C: version 20260625 only
  • Tenda TC3T15C: version 20260625 only

Published 2026-08-13. Last modified 2026-08-14.