Sceawere
Vulnerability Detail
CVE-2026-19749UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Tenda RTSP/ONVIF Missing Authentication
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 2h ago
- Vendor
- Tenda
- Product
- CH7
- Attack Type
- Missing Authentication
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-08-13T21:17:46.557Z",
"pubdate": "2026-08-13T21:17:46.557Z",
"executiveSummary": "A vulnerability has been identified in multiple Tenda device models, specifically CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C, and TC3T15C up to firmware version 20260625. The flaw resides within the RTSP/ONVIF component and involves missing authentication controls, allowing unauthorized entities to interact with vulnerable functions. Although the attack vector is remote, the vulnerability is characterized by high complexity and difficult exploitation requirements. However, because public exploits are now available, the risk profile is elevated, potentially exposing affected Internet-connected IP cameras and smart home devices to unauthorized stream access or device manipulation if proper network boundary defenses are absent.",
"technicalDetails": "The vulnerability stems from an authorization enforcement failure within the RTSP/ONVIF service component of the affected Tenda products. Specifically, the affected component fails to properly validate credentials or session tokens prior to processing protocol-level commands or streaming requests. This lack of access control allows remote attackers to bypass the standard authentication handshake required to access sensitive device functionalities, such as real-time video streaming or ONVIF device management interfaces.\nThe attack flow begins with network reconnaissance to identify exposed RTSP or ONVIF ports on target devices connected to the network or exposed via wide-area networks. Because the vulnerability involves missing authentication, an attacker does not require valid administrative or user credentials. Upon establishing a connection to the vulnerable RTSP/ONVIF endpoint, the attacker can transmit specifically crafted protocol requests that manipulate the underlying component. Due to the high complexity and difficulty of exploitation noted for this flaw, attackers may need to deliver precise sequence payloads or exploit specific timing conditions inherent to the device's multi-threaded media server architecture to achieve successful interaction.\nSuccessful exploitation of this missing authentication vulnerability allows remote adversaries to illicitly access video feeds, query device configuration parameters, or interact with ONVIF management operations without authorization. The vulnerable component is network-exposed by default to facilitate camera monitoring and integration with third-party video management systems (VMS), increasing the attack surface. Affected versions include all firmware builds up to 20260625 across the specified Tenda device lineup. Because no privilege or authentication is verified by the vulnerable component, any remote entity capable of routing packets to the RTSP or ONVIF service ports can potentially trigger the flaw, resulting in a breach of confidentiality and integrity regarding the video surveillance data."
}