CVE-2026-86148

9.1

Tenda · CP3

A remote OS command injection vulnerability exists in Tenda CP3 version 27.5.57.101 within the SystemAsh function, allowing attackers to execute arbitrary commands via the AlarmVoiceURL argument.

Executive summary

A critical OS command injection vulnerability in Tenda CP3 cameras allows remote attackers with administrative privileges to execute arbitrary system commands, potentially leading to full device compromise.

Vulnerability

This flaw is an OS command injection (CWE-78) occurring in the SystemAsh function of the Kylin component. An attacker with administrative privileges can manipulate the AlarmVoiceURL parameter to achieve remote code execution.

Business impact

The exploitation of this vulnerability poses a severe risk to organizational security, as it grants attackers the ability to execute unauthorized commands on the affected device. Given the CVSS score of 9.1, this is classified as a critical risk that could lead to the total compromise of the camera, unauthorized surveillance, or its use as a pivot point for further lateral movement within the internal network.

Remediation

Immediate Action: Contact Tenda support or monitor the official vendor portal for a firmware update that addresses the SystemAsh command injection flaw.

Proactive Monitoring: Review device access logs for suspicious input patterns directed at the AlarmVoiceURL parameter or unusual outbound traffic originating from the camera.

Compensating Controls: Restrict management access to the device by placing the camera on a segmented VLAN and ensuring it is not directly exposed to the public internet via port forwarding.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical nature of command injection vulnerabilities, it is imperative to limit exposure of the Tenda CP3 management interface immediately. Administrators should prioritize the installation of any forthcoming firmware patches from Tenda as soon as they become available to mitigate the risk of unauthorized system access.

More Tenda CVEs all →

Sources

Originally found and disclosed by FengZi (VulDB User), with VulDB Vulnerability Moderation Team (coordinator), per the CVE Program record.