CVE-2026-19750
Received
Received - Intake
Hard-Coded Password in Tenda CH/CP/TX3 Router Firmware
Vulnerability report for CVE-2026-19750, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-13
Last updated on: 2026-08-13
Assigner: VulDB
Description
Description
A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tenda | ch | v21.x |
| tenda | ch | v22.x |
| tenda | ch | v25.x |
| tenda | ch | v26.x |
| tenda | ch | v27.x |
| tenda | cp | v21.x |
| tenda | cp | v22.x |
| tenda | cp | v25.x |
| tenda | cp | v26.x |
| tenda | cp | v27.x |
| tenda | tx3 | v21.x |
| tenda | tx3 | v22.x |
| tenda | tx3 | v25.x |
| tenda | tx3 | v26.x |
| tenda | tx3 | v27.x |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-259 | The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components. |
| CWE-255 |