ZeroHour

CVE-2026-79551

PoC moderate

Hardcoded Cryptographic Key in Tenda NVR_4H CH3 v2.1

CVSS
EPSS
Published
()
Modified
AI analysis

Tenda NVR_4H CH3 v2.1 running firmware V27.5.58.6 contains a hardcoded cryptographic key embedded in the device firmware. An attacker who extracts the key — for example from a downloadable firmware image or via the public proof-of-concept published on GitHub — could use it to defeat the device's cryptographic protections, such as decrypting captured traffic, forging authenticated sessions, or bypassing encryption depending on where the key is used. This affects organizations and home users deploying this Tenda network video recorder model, which is typically used for IP camera surveillance in SMB and residential settings. A public PoC exists, but the CVE is not in the CISA KEV catalog and there is no confirmed evidence of in-the-wild exploitation at this time.

What to do: Check Tenda's official support site for a firmware update for the NVR_4H CH3 and apply it if one addresses this issue; Tenda has not stated a fixed version. In the meantime, remove the NVR from direct internet exposure (place it behind a VPN or firewall), rotate any credentials configured on the device, and monitor logs for unexpected logins or configuration changes. Because a hardcoded key cannot be changed by configuration, isolation and patching are the primary mitigations.

Affected
Tenda Technology Co., Ltd NVR_4H CH3v2.1 (firmware V27.5.58.6)
Estimated exposure
moderatelikely low thousands to ~10,000s of deployed units, with an unknown subset internet-exposed — Tenda is a high-volume budget networking/surveillance vendor and its NVRs are routinely found by internet-wide scans (Shodan/Censys), but no model-specific install or exposure counts are available, so this is a rough order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

In the news

No ingested article mentions this CVE yet.