# Tenda vulnerabilities & exploitation

> As of 2026-10-10, Threadlinqs tracks 6 Tenda CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 4 tracked threat campaigns.

**Data as of:** 2026-10-10

## Exploitation timeline

Threadlinqs has recorded 6 Tenda CVEs published between 2024-09-15 and 2026-09-15. The busiest month was 2026-09 (3 new CVEs). None of them is listed in CISA KEV yet.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 6 of 6 tracked Tenda CVEs.

- [CVE-2024-46048](https://intel.threadlinqs.com/cve/CVE-2024-46048) — HIGH 8.8 · EPSS 10.5% · 2024-09-13
- [CVE-2026-86148](https://intel.threadlinqs.com/cve/CVE-2026-86148) — CRITICAL 9.1 · EPSS 2.5% · 2026-09-05
- [CVE-2026-86149](https://intel.threadlinqs.com/cve/CVE-2026-86149) — CRITICAL 9.1 · EPSS 2% · 2026-09-05
- [CVE-2026-78141](https://intel.threadlinqs.com/cve/CVE-2026-78141) — HIGH 7.4 · EPSS 1.1% · 2026-08-23
- [CVE-2026-11405](https://intel.threadlinqs.com/cve/CVE-2026-11405) — CRITICAL 9.8 · EPSS 0.8% · 2026-07-06
- [CVE-2026-86150](https://intel.threadlinqs.com/cve/CVE-2026-86150) — MEDIUM 4.1 · EPSS 0.2% · 2026-09-05

## Products affected

Threadlinqs normalises CPE and CNA product records across all 6 CVEs; 5 distinct Tenda products are affected. The most frequently affected:

- CP3 — 3 CVEs
- CH22 — 1 CVE
- Fh451 — 1 CVE
- Fh451 Firmware — 1 CVE
- firmware — 1 CVE

## Threat activity

4 tracked threat campaigns reference Tenda products or exploit Tenda CVEs:

- [Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet Exploiting 18 Known CVEs in Internet-Facing Devices](https://intel.threadlinqs.com/threat/TL-2026-3062) — HIGH — 2026-10-09
- [Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394](https://intel.threadlinqs.com/threat/TL-2026-2857) — CRITICAL — 2026-10-03
- [JadeProx: China-Nexus Campaign Deploys TriBack Loader Against Government, Healthcare, and Education Targets in APAC and Latin America](https://intel.threadlinqs.com/threat/TL-2026-1653) — HIGH — 2026-07-23
- [CVE-2026-11405: Undocumented Authentication Backdoor in Tenda Router Firmware (FH1201, W15E, AC10, AC5, AC6)](https://intel.threadlinqs.com/threat/TL-2026-1188) — CRITICAL — 2026-07-10

## How to prioritise Tenda patching

This order follows the data Threadlinqs holds for Tenda, not a generic severity checklist:

- No Tenda CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are [CVE-2024-46048](https://intel.threadlinqs.com/cve/CVE-2024-46048) (10.5%), [CVE-2026-86148](https://intel.threadlinqs.com/cve/CVE-2026-86148) (2.5%), [CVE-2026-86149](https://intel.threadlinqs.com/cve/CVE-2026-86149) (2%).
- 3 CVEs score Critical and 2 High on CVSS v3 (maximum 9.8, average 8); sequence these after KEV and high-EPSS items.
- 2 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-10 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/tenda
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
