Sceawere

Vulnerability Detail

CVE-2026-19747UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Tenda ATE Module Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
Tenda
Product
CH7
Attack Type
Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-13T20:17:21.570Z",
  "pubdate": "2026-08-13T20:17:21.570Z",
  "executiveSummary": "A critical command injection vulnerability has been identified within the ATE Module of multiple Tenda router and camera models, specifically affecting versions up to 20260625. The flaw resides in the CAte::HandleCmd function within the Kylin binary.\nThis vulnerability allows remote threat actors to execute arbitrary system commands on the underlying operating system with the privileges of the affected application.\nAffected products include Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C, and TC3T15C.\nThe risk implications are severe, potentially leading to complete device compromise, unauthorized access to internal network resources, and the establishment of persistent backdoors.\nThe attack can be carried out remotely across the network without requiring prior authentication or user interaction, significantly lowering the barrier to exploitation and increasing overall exposure.",
  "technicalDetails": "The vulnerability is classified as a command injection flaw occurring within the ATE Module of the affected Tenda firmware. Specifically, the weakness manifests in the CAte::HandleCmd function located in the Kylin binary.\nThe root cause of the vulnerability stems from insufficient input sanitization and validation within the command handling logic. When untrusted input is passed to the application, the handler improperly constructs system execution strings, allowing malicious payload data to be interpreted directly as shell commands by the underlying operating system.\nExploitation of this vulnerability requires network connectivity to the target device. Because the attack vector is exposed remotely, an unauthenticated attacker can transmit a crafted request containing malicious command payloads directly to the vulnerable service listening on the device.\nThe step-by-step attack flow proceeds as follows: First, the attacker identifies the exposed network service hosting the ATE Module. Second, the attacker crafts a specialized input payload designed to break out of the intended argument context within the CAte::HandleCmd function, appending arbitrary system commands using shell metacharacters. Third, the crafted request is transmitted over the network to the target device. Fourth, the Kylin binary processes the input within the vulnerable function, passing the unsanitized string to the underlying system shell for execution. Finally, the injected commands execute with the elevated privileges associated with the running process, yielding full control to the adversary.\nThe affected versions encompass all firmware releases up to 20260625 for the specified Tenda device models. Successful exploitation results in post-exploitation impact such as arbitrary code execution, system manipulation, unauthorized data exfiltration, and potential lateral movement within the local network environment."
}
CVE-2026-19747: Tenda ATE Module Command Injection (CRITICAL Severity, CVSS: 9.8) - Sceawere