CVE-2026-19748
Deferred Deferred - Pending Action

Insufficient Entropy in Tenda Kylin Web Service

Vulnerability report for CVE-2026-19748, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-14

Assigner: VulDB

Description

A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to insufficient entropy. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-14
Generated
2026-09-03
AI Q&A
2026-08-14
EPSS Evaluated
2026-09-02
NVD
EUVD

Affected Vendors & Products

Showing 10 associated CPEs
Vendor Product Version / Range
tenda ch7 *
tenda ch7g *
tenda ch10 *
tenda cp3 *
tenda cp3_pro *
tenda cp7 *
tenda tc3b14c *
tenda tc3b15c *
tenda tc3t14c *
tenda tc3t15c to 20260625 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-330 The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
CWE-331 The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects multiple Tenda devices due to insufficient entropy in session token generation. The flaw exists in the Kylin Web Service component, specifically in the CWebSessionManager_ParseSession function. An attacker could manipulate the SESSION argument to potentially bypass security controls, though the attack is described as highly complex and difficult to exploit.

Detection Guidance

This vulnerability involves insufficient entropy in session tokens due to manipulation of the SESSION argument in the Kylin Web Service. Detection requires checking for predictable session tokens or unusual session handling in affected Tenda devices. No specific commands are provided in the context, but monitoring for weak session token generation or unexpected web service behavior may help identify potential exploitation attempts.

Impact Analysis

If exploited, this vulnerability could allow unauthorized access to the device's web interface or services. An attacker might gain control over the device, steal sensitive data, or perform actions on behalf of legitimate users. However, the difficulty of exploitation and lack of known public exploits reduce immediate risk.

Compliance Impact

The vulnerability involves insufficient entropy in session tokens, which could allow unauthorized access to sensitive data. This may impact compliance with GDPR (data protection) and HIPAA (health data security) by increasing the risk of data breaches or unauthorized access to personal or health information.

Mitigation Strategies

Immediately update affected Tenda devices to firmware versions beyond 20260625. Disable remote access to the Kylin Web Service if not required. Monitor network traffic for unusual session-related activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19748. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart