CVE-2026-86149
9.1Tenda · CP3
Tenda CP3 version 27.5.57.101 is vulnerable to remote OS command injection via the interface_name or host arguments in Net/NetCheckPing.cpp.
Executive summary
A critical OS command injection vulnerability in Tenda CP3 version 27.5.57.101 allows remote attackers to execute arbitrary commands on the underlying system.
Vulnerability
This vulnerability occurs in the Net/NetCheckPing.cpp file, where insufficient validation of the interface_name or host arguments allows an attacker to inject and execute arbitrary OS commands. This can be triggered remotely.
Business impact
The CVSS score of 9.1 underscores the critical impact of this vulnerability. Successful command injection allows an attacker to execute arbitrary code with system-level privileges, resulting in full control over the affected device, potential data exfiltration, and the ability to use the device as a pivot point for further network attacks.
Remediation
Immediate Action: Monitor the Tenda official support portal for firmware updates and apply them as soon as they become available.
Proactive Monitoring: Monitor network traffic for suspicious command-line patterns or unexpected outbound connections from the Tenda CP3 device.
Compensating Controls: Ensure the device management interface is not exposed to the internet and utilize a WAF or firewall to block requests containing malicious command patterns if possible.
Exploitation status
Public Exploit Available: Unknown; no confirmed public exploit or weaponized module is currently identified.
Analyst recommendation
This vulnerability is highly critical and presents a significant risk of remote code execution. It is imperative to restrict access to the device management functions from untrusted networks immediately. Organizations should verify that these devices are not directly reachable from the internet while awaiting a vendor-supplied patch.
More Tenda CVEs all →
Sources
Originally found and disclosed by FengZi (VulDB User), with VulDB Vulnerability Moderation Team (coordinator), per the CVE Program record.
- VDB-399272 | Tenda CP3 NetCheckPing.cpp os command injection Vulnerability database entry
- VDB-399272 | CTI Indicators (IOB, IOC, TTP, IOA)
- CVE-2026-86149 | CVE Analysis and Report Third-party advisory
- Submit #895350 | Tenda CP3 V3.2 V27.5.57.101 OS Command Injection Third-party advisory
- tenda.com.cn