← Terug naar overzicht

A critical OS command injection vulnerability has been identified in Tenda CP3 firmware version 27.5.57.101. The flaw resides in the function CAutoAddWifi::ThreadProc within the file Functions/AutoAddWifi.cpp, part of the Kylin component. An attacker can exploit this vulnerability by manipulating inputs to execute arbitrary OS commands on the affected device. The attack can be launched remotely without requiring physical access to the device. This poses a significant security risk to users of the affected Tenda CP3 device running the specified firmware version. The vulnerability has been reported via VulDB and tracked under CVE-2026-86152.

Affected products

  • Tenda CP3 27.5.57.101

Related CVE's

  • CVE-2026-86152

Categories

  • Mobile & IoT
  • Network Infrastructure