← Terug naar overzicht

A critical OS command injection vulnerability has been identified in Tenda CP3 firmware version 27.5.57.101. The flaw resides in the file Net/NetCheckPing.cpp, where improper handling of the arguments interface_name and host allows an attacker to inject arbitrary OS commands. The vulnerability can be exploited remotely without requiring physical access to the device. Successful exploitation could allow an attacker to execute arbitrary commands on the affected device, potentially leading to full system compromise. The issue is tracked as CVE-2026-86149 and has been assigned a high severity rating. Tenda CP3 is a network camera/IP device, making this vulnerability particularly concerning for IoT and network security environments. No patch details are currently available in the article, and users are advised to monitor vendor advisories from Tenda.

Affected products

  • Tenda CP3 27.5.57.101

Related CVE's

  • CVE-2026-86149

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities