← Back to overview

A vulnerability has been identified in Tenda CP3 firmware version 27.5.57.101 affecting the function CRedirServer::SetRedirectEnable in the file Functions/Redirect.cpp. The flaw involves improper privilege management that can be triggered through manipulation of this function. The vulnerability is remotely exploitable, meaning an attacker does not need local access to the device. Tenda CP3 is a network device, making this vulnerability particularly relevant to network infrastructure security. The issue has been catalogued under CVE-2026-86153 and is referenced across multiple vulnerability databases including NVD and VulDB. No patch or mitigation details are explicitly mentioned in the article. The remote exploitability increases the risk profile for affected deployments.

Affected products

  • Tenda CP3 27.5.57.101

Related CVE's

  • CVE-2026-86153

Categories

  • Identity & Access
  • Mobile & IoT
  • Network Infrastructure