AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19748

LOW · CVSS 3.7 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C, and TC3T15C devices are vulnerable due to insufficient entropy in the CWebSessionManager_ParseSession function of the Kylin Web Service, which can be exploited remotely. Although the vulnerability has a low severity rating and is considered difficult to exploit, it may still allow attackers to manipulate session management processes. Organizations using these devices should prioritize monitoring and applying mitigations to safeguard against potential complex attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19748
Severity
LOW
CVSS
3.7
EPSS
0.31%

Original NVD Description

A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to insufficient entropy. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult.