AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19750

HIGH · CVSS 8.1 EPSS 0.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A vulnerability exists in the SSH component of Tenda CH, CP, and TX3 firmware versions V21.x through V27.x, allowing attackers to exploit a hard-coded password. This flaw can be exploited remotely, posing a significant risk of unauthorized access, although the complexity of the attack may deter some threat actors. Organizations using affected Tenda products should prioritize patching to mitigate potential breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19750
Severity
HIGH
CVSS
8.1
EPSS
0.47%

Original NVD Description

A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used.