← Terug naar overzicht

A vulnerability was identified in Tenda CP3 firmware version 27.5.57.101 affecting the function sub_2F77E8 in the file Apis/system.c within the Network Configuration Management component. The flaw allows attackers to perform OS command injection through manipulation of the affected function. The attack can be initiated remotely without requiring physical access to the device. This type of vulnerability is particularly dangerous as it can allow full system compromise via arbitrary command execution. The affected product is a networking device manufactured by Tenda, a Chinese networking hardware company. No patch or mitigation details are mentioned in the article. The vulnerability has been assigned CVE-2026-86151 and is tracked in both NVD and VulDB databases.

Affected products

  • Tenda CP3 27.5.57.101

Related CVE's

  • CVE-2026-86151

Categories

  • Mobile & IoT
  • Network Infrastructure