SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-19747 2026-08-13

CVE-2026-19747: Unauthenticated Command Injection in Tenda Smart Cameras

"A critical (CVSS 9.8) command injection flaw in the ATE Module of ten Tenda camera models allows remote, unauthenticated attackers to execute arbitrary commands."

A critical (CVSS 9.8) command injection flaw in the ATE Module of ten Tenda camera models allows remote, unauthenticated attackers to execute arbitrary commands.

What Is It

CVE-2026-19747 is a command injection vulnerability (CWE-74 / CWE-77) in the CAte::HandleCmd function of the file Kylin, part of the ATE Module shipped in Tenda camera firmware up to build 20260625. Manipulation of input handled by this function results in command injection, and the attack can be carried out remotely.

The CVE was published on 2026-08-13 by VulDB ([email protected]) and currently carries NVD status "Received."

Why It Matters

The CVSS 3.1 base score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low attack complexity, no privileges, and no user interaction required, with high impact to confidentiality, integrity, and availability. The CVSS 4.0 assessment scores it 8.9 (HIGH) and sets exploit maturity to PROOF_OF_CONCEPT, a rating that indicates proof-of-concept material is publicly available; it does not by itself establish that a reliable, weaponized exploit exists. A write-up is hosted in a public GitHub repository.

There is no CISA KEV entry for this CVE in the supplied data, so active in-the-wild exploitation is not confirmed and no KEV remediation deadline applies.

What's Vulnerable

Tenda devices running firmware up to 20260625, component ATE Module:

Patch Status

No patch, fixed version, or vendor advisory is present in the supplied source material. The only vendor reference available is Tenda's website. Until a fixed firmware build is confirmed, treat these devices as exposed: restrict network reachability of affected cameras, keep them off internet-facing segments, and monitor the vendor site and VulDB entry for a remediation update.

Sources