{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/tc3b15c/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-19747"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CH7","CH7G","CH10","CP3","CP3 Pro","CP7","TC3B14C","TC3B15C","TC3T14C","TC3T15C"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Tenda"],"content_html":"\u003cp\u003eA critical command injection vulnerability (CVE-2026-19747) has been identified in the ATE module of several Tenda smart camera models, including the CH7, CH7G, CH10, CP3, CP3 Pro, CP7, and various TC3-series variants. The flaw exists within the 'CAte::HandleCmd' function contained in the 'Kylin' file. By sending specially crafted requests, a remote, unauthenticated attacker can trigger this vulnerability to execute arbitrary system commands on the targeted device. Affected firmware versions include all builds up to 20260625. This vulnerability is particularly concerning due to its remote, unauthenticated nature and the high likelihood of resulting in full device compromise, potentially enabling attackers to pivot into the local network or integrate the cameras into botnets.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify accessible Tenda smart camera interfaces.\u003c/li\u003e\n\u003cli\u003eAttacker probes the device's web or command-handling API to target the ATE module.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious request string containing shell metacharacters intended for the 'CAte::HandleCmd' function.\u003c/li\u003e\n\u003cli\u003eAttacker transmits the crafted request to the camera's network port.\u003c/li\u003e\n\u003cli\u003eThe 'Kylin' component processes the input without sufficient sanitization of the input parameters.\u003c/li\u003e\n\u003cli\u003eThe underlying system shell interprets and executes the injected malicious commands.\u003c/li\u003e\n\u003cli\u003eAttacker achieves command execution with system-level privileges on the camera.\u003c/li\u003e\n\u003cli\u003eAttacker establishes persistent access or exfiltrates device configuration data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full control of the affected smart camera, potentially enabling the use of the device for unauthorized surveillance, lateral movement within the network, or participation in distributed denial-of-service (DDoS) campaigns. Given the ubiquity of these devices in home and small office environments, the exposure of these credentials or local network access presents a significant security risk to end users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and inventory all Tenda camera models listed in the affected products section within the local network.\u003c/li\u003e\n\u003cli\u003eRestrict network access to these camera interfaces to trusted management subnets to prevent remote exploitation from the internet.\u003c/li\u003e\n\u003cli\u003eContact Tenda for firmware updates that address the 'CAte::HandleCmd' command injection vulnerability and apply them immediately.\u003c/li\u003e\n\u003cli\u003eMonitor perimeter and internal network logs for abnormal HTTP or API traffic directed at Tenda devices, specifically looking for unusual shell syntax in request parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T22:04:52Z","date_published":"2026-08-13T22:04:52Z","id":"https://feed.craftedsignal.io/briefs/2026-08-tenda-rce/","summary":"Multiple Tenda smart camera models are susceptible to unauthenticated remote command injection via the 'CAte::HandleCmd' function, allowing attackers to execute arbitrary system commands.","title":"Command Injection Vulnerability in Tenda Smart Camera ATE Module","url":"https://feed.craftedsignal.io/briefs/2026-08-tenda-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - TC3B15C","version":"https://jsonfeed.org/version/1.1"}