Sceawere

Vulnerability Detail

CVE-2026-19748UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Tenda Kylin Insufficient Entropy Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.7
Creation Date
2h ago
Vendor
Tenda
Product
CH7
Attack Type
Insufficient Entropy
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to insufficient entropy. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.7",
  "pubDate": "2026-08-13T21:17:46.343Z",
  "pubdate": "2026-08-13T21:17:46.343Z",
  "executiveSummary": "A security vulnerability has been identified affecting multiple Tenda router and camera models, specifically Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C, and TC3T15C up to firmware versions dated 20260625. The flaw resides within the Kylin Web Service component, specifically inside the binary file /user/bin/Kylin, affecting the function CWebSessionManager_ParseSession. The root cause of this vulnerability stems from insufficient entropy when handling the SESSION argument, leading to weak session identifier generation. This cryptographic weakness allows remote threat actors to successfully brute-force or predict active session tokens. Successful exploitation of this vulnerability can lead to unauthorized access, session hijacking, and complete compromise of the affected IoT and networking devices. Although the attack vector is remote, the overall exploitability is rated as difficult due to the high complexity required to successfully predict or brute-force the low-entropy tokens under real-world conditions.",
  "technicalDetails": "The vulnerability is localized to the Kylin Web Service component running on the affected Tenda device models. During the session management lifecycle, the binary /user/bin/Kylin processes incoming HTTP requests via the CWebSessionManager_ParseSession function. Specifically, this function parses and validates the SESSION argument provided by clients to authenticate ongoing sessions.\nThe root cause of the vulnerability is the implementation of a pseudo-random number generator (PRNG) or seed mechanism that fails to provide sufficient cryptographic entropy. Insufficient entropy results in session identifiers that are predictable or constrained within a limited keyspace. Because the generation mechanism lacks adequate randomness, the resulting session tokens do not possess the required bit-strength to resist targeted guessing attacks.\nThe attack flow proceeds as follows: A remote attacker initiates communication with the device's web interface exposed over the network. By interacting with the authentication or session parsing routines, the attacker analyzes the structure and generation pattern of session tokens assigned by the CWebSessionManager_ParseSession function. Due to the lack of sufficient entropy, the attacker can leverage computational algorithms or brute-force methodologies against the SESSION argument. Once a valid or predicted session token is calculated or guessed, the attacker transmits the crafted token back to the device within the SESSION parameter. The vulnerable function parses the supplied identifier, fails to validate its cryptographic strength, and erroneously accepts it as a legitimate authenticated session.\nNetwork exposure for this component is remote, meaning attackers do not require physical access to the target device, provided the management interface is accessible via the local network or the internet. Authentication requirements are effectively bypassed, as the vulnerability itself targets the authentication and session management mechanism. Privilege requirements are low from an attacker's perspective, as unauthenticated remote entities can attempt session prediction. The post-exploitation impact includes full administrative session hijacking, unauthorized configuration modifications, exposure of sensitive device internals, and potential lateral movement or persistent compromise of the host device."
}
CVE-2026-19748: Tenda Kylin Insufficient Entropy Vulnerability (LOW Severity, CVSS: 3.7) - Sceawere