RTSP/ONVIF Authentication Flaw in Tenda Devices
CVE-2026-19749
6.3MEDIUM
What is CVE-2026-19749?
A significant vulnerability has been identified in several Tenda devices, including the CH7, CH7G, CH10, and others. This issue lies within the RTSP/ONVIF component, where a manipulation can lead to missing authentication. An attacker can exploit this flaw remotely, potentially allowing unauthorized access to the affected devices. Exploiting this vulnerability requires a certain level of complexity, and while the attack is considered challenging, tools have been made publicly available which could facilitate its execution.
Affected Version(s)
CH10 20260625
CH7 20260625
CH7G 20260625