A critical security vulnerability has been identified in Tenda CP3 firmware version 27.5.57.101. The flaw resides in the SystemAsh function within the file Apis/system.c, part of the Kylin component. By manipulating the AlarmVoiceURL argument, an attacker can perform OS command injection. The vulnerability is remotely exploitable, requiring no physical access to the target device. This type of vulnerability poses a significant risk as it can allow attackers to execute arbitrary system commands. Successful exploitation could lead to full device compromise, data exfiltration, or use of the device in further attacks. The vulnerability has been assigned CVE-2026-86148 and is catalogued in both NVD and VulDB databases. Tenda CP3 is a network-connected security camera device, making this vulnerability particularly concerning for IoT and surveillance infrastructure deployments.