Sceawere

Vulnerability Detail

CVE-2026-19750UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Tenda SSH Hard-Coded Password Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
Tenda
Product
CH
Attack Type
Use of Hard-coded Password
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-13T22:17:19.290Z",
  "pubdate": "2026-08-13T22:17:19.290Z",
  "executiveSummary": "A security vulnerability has been identified within the SSH component of Tenda CH, CP, and TX3 routers across multiple firmware versions (V21.x, V22.x, V25.x, V26.x, and V27.x). This vulnerability stems from the implementation of a hard-coded password within the affected software functionality. Successful exploitation of this flaw can allow unauthorized remote actors to bypass standard authentication mechanisms and gain unauthorized access to the underlying system.\nThe risk implications are severe, as compromise of network edge devices typically grants attackers a persistent foothold, potential man-in-the-middle capabilities, and internal network visibility. According to threat intelligence indicators, an exploit has been publicly released, raising the probability of active exploitation in the wild.\nDespite the availability of a public exploit, the attack vector requires a high level of complexity, and the practical execution of the exploit is characterized as difficult. Attackers must possess specific networking knowledge and target the exposed SSH daemon directly. The vulnerability can be exploited remotely over the network, bypassing local physical access constraints. Organizations utilizing the affected Tenda product lines face significant security exposure until remediation measures are applied.",
  "technicalDetails": "The vulnerability resides in the SSH component utilized across Tenda CH, CP, and TX3 V21.x, V22.x, V25.x, V26.x, and V27.x firmware versions. The root cause of the security defect is the inclusion of a hard-coded static credential embedded directly within the firmware binaries or configuration files associated with the secure shell service.\nNetwork exposure is a primary factor in this vulnerability, as the affected SSH service listens on network interfaces and is accessible remotely. Attackers do not require prior administrative privileges or valid user credentials to interact with the vulnerable service; however, successful exploitation relies on leveraging the embedded static password known to exist within the affected software builds.\nThe attack flow proceeds as follows: First, the remote threat actor performs network reconnaissance to identify exposed SSH services running on target Tenda devices within the supported firmware ranges (V21.x through V27.x). Upon confirming the target runs an affected firmware version, the attacker initiates an SSH connection to the device's management interface or exposed daemon port. Second, rather than utilizing dynamic or user-provisioned credentials, the attacker authenticates against the SSH service using the discovered hard-coded password. Because the device accepts these embedded credentials without validation against a secure, modifiable credential store, the authentication handshake succeeds. Finally, upon successful authentication, the attacker is granted interactive shell access to the device with the privileges associated with the SSH service account, typically root or administrative privilege levels.\nThe post-exploitation impact includes full administrative control over the compromised Tenda router. An adversary with root-level access can modify system configurations, intercept or manipulate network traffic traversing the device, deploy persistent backdoors, utilize the router as a pivot point to attack internal local area network (LAN) resources, or disable security logging mechanisms to hinder forensic investigation. Given that an exploit has been published, automated scanning and exploitation scripts may actively target exposed instances."
}
CVE-2026-19750: Tenda SSH Hard-Coded Password Vulnerability (HIGH Severity, CVSS: 8.1) - Sceawere