CVE-2026-19750: Tenda Ch

High severity, CVSS 8.1. EPSS: 0.8% chance of exploitation in the next 30 days.

A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used.

Affected products

  • Tenda Ch: from 21, before 22 (fixed in 22); from 22, before 23 (fixed in 23); from 25, before 26 (fixed in 26); from 26, before 27 (fixed in 27); from 27, before 28 (fixed in 28)
  • Tenda CP: from 21, before 22 (fixed in 22); from 22, before 23 (fixed in 23); from 25, before 26 (fixed in 26); from 26, before 27 (fixed in 27); from 27, before 28 (fixed in 28)
  • Tenda TX3: from 21, before 22 (fixed in 22); from 22, before 23 (fixed in 23); from 25, before 26 (fixed in 26); from 26, before 27 (fixed in 27); from 27, before 28 (fixed in 28)

Published 2026-08-13. Last modified 2026-08-14.