{"api_version":"1","generated_at":"2026-08-14T19:41:43+00:00","cve":"CVE-2026-19749","urls":{"html":"https://cve.report/CVE-2026-19749","api":"https://cve.report/api/cve/CVE-2026-19749.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-19749","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-19749"},"summary":{"title":"Tenda CH7 RTSP/ONVIF missing authentication","description":"A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used.","state":"PUBLISHED","assigner":"VulDB","published_at":"2026-08-13 21:17:46","updated_at":"2026-08-14 19:09:56"},"problem_types":["CWE-287","CWE-306","CWE-306 Missing Authentication","CWE-287 Improper Authentication"],"metrics":[{"version":"4.0","source":"cna@vuldb.com","type":"Secondary","score":"2.9","severity":"LOW","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.9,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"DECLARED","score":"6.3","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","data":{"baseScore":6.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","version":"4.0"}},{"version":"3.1","source":"cna@vuldb.com","type":"Primary","score":"3.7","severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"3.7","severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R","data":{"baseScore":3.7,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R","version":"3.1"}},{"version":"3.0","source":"CNA","type":"DECLARED","score":"3.7","severity":"LOW","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R","data":{"baseScore":3.7,"baseSeverity":"LOW","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R","version":"3.0"}},{"version":"2.0","source":"cna@vuldb.com","type":"Secondary","score":"2.6","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"CNA","type":"DECLARED","score":"2.6","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:W/RC:UR","data":{"baseScore":2.6,"vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:W/RC:UR","version":"2.0"}}],"references":[{"url":"https://vuldb.com/submit/868503","name":"https://vuldb.com/submit/868503","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/howitouchyou/Tenda-Smart-Camera-Vulnerability/blob/main/Tenda%20RTSP_ONVIF%20Auth%20Bypass/Tenda%20RTSP_ONVIF%20Auth%20Bypass.md","name":"https://github.com/howitouchyou/Tenda-Smart-Camera-Vulnerability/blob/main/Tenda%20RTSP_ONVIF%20Auth%20Bypass/Tenda%20RTSP_ONVIF%20Auth%20Bypass.md","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.tenda.com.cn/","name":"https://www.tenda.com.cn/","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/cve/CVE-2026-19749","name":"https://vuldb.com/cve/CVE-2026-19749","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/vuln/389500","name":"https://vuldb.com/vuln/389500","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/vuln/389500/cti","name":"https://vuldb.com/vuln/389500/cti","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-19749","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19749","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Tenda","product":"CH7","version":"affected 20260625","platforms":[]},{"source":"CNA","vendor":"Tenda","product":"CH7G","version":"affected 20260625","platforms":[]},{"source":"CNA","vendor":"Tenda","product":"CH10","version":"affected 20260625","platforms":[]},{"source":"CNA","vendor":"Tenda","product":"CP3","version":"affected 20260625","platforms":[]},{"source":"CNA","vendor":"Tenda","product":"CP3 Pro","version":"affected 20260625","platforms":[]},{"source":"CNA","vendor":"Tenda","product":"CP7","version":"affected 20260625","platforms":[]},{"source":"CNA","vendor":"Tenda","product":"TC3B14C","version":"affected 20260625","platforms":[]},{"source":"CNA","vendor":"Tenda","product":"TC3B15C","version":"affected 20260625","platforms":[]},{"source":"CNA","vendor":"Tenda","product":"TC3T14C","version":"affected 20260625","platforms":[]},{"source":"CNA","vendor":"Tenda","product":"TC3T15C","version":"affected 20260625","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-08-13T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"source":"CNA","time":"2026-08-13T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"source":"CNA","time":"2026-08-13T16:44:54.000Z","lang":"en","value":"VulDB entry last update"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Howitouchyou (VulDB User)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:h:tenda:ch7:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"product":"CH7","vendor":"Tenda","versions":[{"status":"affected","version":"20260625"}]},{"cpes":["cpe:2.3:h:tenda:ch7g:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"product":"CH7G","vendor":"Tenda","versions":[{"status":"affected","version":"20260625"}]},{"cpes":["cpe:2.3:h:tenda:ch10:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"product":"CH10","vendor":"Tenda","versions":[{"status":"affected","version":"20260625"}]},{"cpes":["cpe:2.3:h:tenda:cp3:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"product":"CP3","vendor":"Tenda","versions":[{"status":"affected","version":"20260625"}]},{"cpes":["cpe:2.3:h:tenda:cp3_pro:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"product":"CP3 Pro","vendor":"Tenda","versions":[{"status":"affected","version":"20260625"}]},{"cpes":["cpe:2.3:h:tenda:cp7:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"product":"CP7","vendor":"Tenda","versions":[{"status":"affected","version":"20260625"}]},{"cpes":["cpe:2.3:h:tenda:tc3b14c:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"product":"TC3B14C","vendor":"Tenda","versions":[{"status":"affected","version":"20260625"}]},{"cpes":["cpe:2.3:h:tenda:tc3b15c:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"product":"TC3B15C","vendor":"Tenda","versions":[{"status":"affected","version":"20260625"}]},{"cpes":["cpe:2.3:h:tenda:tc3t14c:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"product":"TC3T14C","vendor":"Tenda","versions":[{"status":"affected","version":"20260625"}]},{"cpes":["cpe:2.3:h:tenda:tc3t15c:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"product":"TC3T15C","vendor":"Tenda","versions":[{"status":"affected","version":"20260625"}]}],"credits":[{"lang":"en","type":"reporter","value":"Howitouchyou (VulDB User)"}],"descriptions":[{"lang":"en","value":"A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used."}],"metrics":[{"cvssV4_0":{"baseScore":6.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","version":"4.0"}},{"cvssV3_1":{"baseScore":3.7,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R","version":"3.1"}},{"cvssV3_0":{"baseScore":3.7,"baseSeverity":"LOW","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R","version":"3.0"}},{"cvssV2_0":{"baseScore":2.6,"vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:W/RC:UR","version":"2.0"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"Missing Authentication","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-287","description":"Improper Authentication","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-13T20:45:09.628Z","orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB"},"references":[{"name":"VDB-389500 | Tenda CH7 RTSP/ONVIF missing authentication","tags":["vdb-entry"],"url":"https://vuldb.com/vuln/389500"},{"name":"VDB-389500 | CTI Indicators (IOB, IOC)","tags":["signature","permissions-required"],"url":"https://vuldb.com/vuln/389500/cti"},{"name":"CVE-2026-19749 | CVE Analysis and Report","tags":["third-party-advisory"],"url":"https://vuldb.com/cve/CVE-2026-19749"},{"name":"Submit #868503 | Tenda Tenda Multiple IP Cameras Multiple Versions Missing Authentication","tags":["third-party-advisory"],"url":"https://vuldb.com/submit/868503"},{"tags":["related"],"url":"https://github.com/howitouchyou/Tenda-Smart-Camera-Vulnerability/blob/main/Tenda%20RTSP_ONVIF%20Auth%20Bypass/Tenda%20RTSP_ONVIF%20Auth%20Bypass.md"},{"tags":["product"],"url":"https://www.tenda.com.cn/"}],"timeline":[{"lang":"en","time":"2026-08-13T00:00:00.000Z","value":"Advisory disclosed"},{"lang":"en","time":"2026-08-13T02:00:00.000Z","value":"VulDB entry created"},{"lang":"en","time":"2026-08-13T16:44:54.000Z","value":"VulDB entry last update"}],"title":"Tenda CH7 RTSP/ONVIF missing authentication","x_generator":["VulDB PVTS v202608"]}},"cveMetadata":{"assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","assignerShortName":"VulDB","cveId":"CVE-2026-19749","datePublished":"2026-08-13T20:45:09.628Z","dateReserved":"2026-08-13T14:39:36.955Z","dateUpdated":"2026-08-13T20:45:09.628Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-13 21:17:46","lastModifiedDate":"2026-08-14 19:09:56","problem_types":["CWE-287","CWE-306","CWE-306 Missing Authentication","CWE-287 Improper Authentication"],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.9,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"19749","Ordinal":"1","Title":"Tenda CH7 RTSP/ONVIF missing authentication","CVE":"CVE-2026-19749","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"19749","Ordinal":"1","NoteData":"A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used.","Type":"Description","Title":"Tenda CH7 RTSP/ONVIF missing authentication"}]}}}