CVE-2026-79551
PoC moderateHardcoded Cryptographic Key in Tenda NVR_4H CH3 v2.1
Tenda NVR_4H CH3 v2.1 running firmware V27.5.58.6 contains a hardcoded cryptographic key embedded in the device firmware. An attacker who extracts the key — for example from a downloadable firmware image or via the public proof-of-concept published on GitHub — could use it to defeat the device's cryptographic protections, such as decrypting captured traffic, forging authenticated sessions, or bypassing encryption depending on where the key is used. This affects organizations and home users deploying this Tenda network video recorder model, which is typically used for IP camera surveillance in SMB and residential settings. A public PoC exists, but the CVE is not in the CISA KEV catalog and there is no confirmed evidence of in-the-wild exploitation at this time.
What to do: Check Tenda's official support site for a firmware update for the NVR_4H CH3 and apply it if one addresses this issue; Tenda has not stated a fixed version. In the meantime, remove the NVR from direct internet exposure (place it behind a VPN or firewall), rotate any credentials configured on the device, and monitor logs for unexpected logins or configuration changes. Because a hardcoded key cannot be changed by configuration, isolation and patching are the primary mitigations.
| Tenda Technology Co., Ltd NVR_4H CH3 | v2.1 (firmware V27.5.58.6) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.
In the news0 stories
No ingested article mentions this CVE yet.