CVE detail
CVE-2026-19748
A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to insufficient entropy. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 6
- within the 30d window
- Peak daily
- 6
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://www.tenda.com.cn/www.tenda.com.cn
No excerpt available.
Third Party Advisorywww.tenda.com.cnAug 13, 2026, 9:17 PM - https://vuldb.com/vuln/389499/ctivuldb.com
No excerpt available.
Exploitvuldb.comAug 13, 2026, 9:17 PM - https://vuldb.com/vuln/389499vuldb.com
No excerpt available.
Exploitvuldb.comAug 13, 2026, 9:17 PM - https://vuldb.com/submit/868490vuldb.com
No excerpt available.
Exploitvuldb.comAug 13, 2026, 9:17 PM - https://vuldb.com/cve/CVE-2026-19748vuldb.com
No excerpt available.
Exploitvuldb.comAug 13, 2026, 9:17 PM No excerpt available.
Exploitgithub.comAug 13, 2026, 9:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-42155CVSS 9.3 · Critical
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backwa…
- CVE-2025-6931CVSS 2.9 · Low
A vulnerability classified as problematic was found in D-Link DCS-6517 and DCS-7517 up to 2.02.0. Affected by this vulnerability is the function generate_pass_from_mac of the file…
- CVE-2024-20331CVSS 6.8 · Medium
A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Def…
- CVE-2023-4344CVSS 9.8 · Critical
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
- CVE-2020-36732CVSS 5.3 · Medium
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
- CVE-2021-4241CVSS 2.6 · Low
A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedIn of the file src/psm/Service/User.php. The manipulation le…