Executive brief
Tenda smart cameras in multiple product lines are shipped with RTSP and ONVIF services disabled by default when configured in Simplified Chinese. This allows attackers on the network to access the live video stream and perform device management functions (such as pan-tilt-zoom control) without supplying any password or credentials. An attacker can watch video feeds and control camera functions from anywhere with network access to the device.
Technical details
This is a missing authentication vulnerability caused by insecure default configuration in the Kylin OEM module used across affected Tenda smart cameras. When the device language is set to Simplified Chinese, the firmware initializes both RTSPSecurity and OnvifSecurity configuration flags to 0 (disabled), while other languages default to 1 (enabled). An attacker with network access can connect directly to the RTSP service to obtain the live video stream or use an ONVIF-compatible client to discover the device and access management functions, all without authentication. No credentials, session tokens, or user interaction are required. The vulnerability affects multiple product lines (CH, CP, TC3 series) across a range of firmware versions released through at least mid-2026, and patches appear to be unavailable.
Affected products
- Tenda CH7 V26.5.59.2 and earlier
- Tenda CH7G V26.5.60.2 and earlier
- Tenda CH10 V26.4.41.36 and earlier
- Tenda CP3 V22.5.4.110, V27.5.52.11, V27.5.52.17, V27.5.57.17 and earlier
- Tenda CP3 Pro V21.7.17.111 and earlier
- Tenda CP7 V26.5.45.17 and earlier
- Tenda TC3B14C V25.4.25.53, V25.4.42.20, V25.4.42.21 and earlier
- Tenda TC3B15C V25.4.26.52, V25.4.26.53 and earlier
- Tenda TC3T14C V25.4.43.20 and earlier
- Tenda TC3T15C V25.4.43.21 and earlier
Timeline
- 2026-08-13: disclosed