CVE-2026-86151
9.1Tenda · CP3
A remote OS command injection vulnerability exists in Tenda CP3 version 27.5.57.101, specifically within the Network Configuration Management component.
Executive summary
Tenda CP3 devices are vulnerable to remote OS command injection, posing a critical risk of full system compromise for administrative users.
Vulnerability
This is an OS command injection flaw (CWE-78) located in the sub_2F77E8 function of Apis/system.c. The vulnerability allows an attacker with high privileges to execute arbitrary system commands remotely.
Business impact
Successful exploitation of this vulnerability permits an attacker to execute arbitrary OS commands with high-level privileges, leading to a complete compromise of the device. Given the CVSS score of 9.1, this represents a critical risk that could facilitate unauthorized network access, data exfiltration, or the use of the device as a pivot point for further attacks on the internal network.
Remediation
Immediate Action: Since no specific patch version is currently identified, contact Tenda support or monitor the official Tenda security portal for firmware updates addressing this flaw.
Proactive Monitoring: Review system logs for unusual process execution or unauthorized configuration changes within the Network Configuration Management module.
Compensating Controls: Restrict administrative access to the management interface to trusted IP addresses only, and employ a network firewall to block unauthorized remote access to the device management ports.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Due to the critical nature of this OS command injection vulnerability, organizations using Tenda CP3 hardware must prioritize the identification and isolation of affected units. Until a vendor-supplied patch is verified and deployed, restrict administrative access to the device management interface to mitigate the risk of remote exploitation.
More Tenda CVEs all →
Sources
Originally found and disclosed by FengZi (VulDB User), with VulDB Vulnerability Moderation Team (coordinator), per the CVE Program record.
- VDB-399274 | Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection Vulnerability database entry
- VDB-399274 | CTI Indicators (IOB, IOC, TTP, IOA)
- CVE-2026-86151 | CVE Analysis and Report Third-party advisory
- Submit #895352 | Tenda CP3 V3.2 V27.5.57.101 OS Command Injection Third-party advisory
- tenda.com.cn