CVE-2026-86151

9.1

Tenda · CP3

A remote OS command injection vulnerability exists in Tenda CP3 version 27.5.57.101, specifically within the Network Configuration Management component.

Executive summary

Tenda CP3 devices are vulnerable to remote OS command injection, posing a critical risk of full system compromise for administrative users.

Vulnerability

This is an OS command injection flaw (CWE-78) located in the sub_2F77E8 function of Apis/system.c. The vulnerability allows an attacker with high privileges to execute arbitrary system commands remotely.

Business impact

Successful exploitation of this vulnerability permits an attacker to execute arbitrary OS commands with high-level privileges, leading to a complete compromise of the device. Given the CVSS score of 9.1, this represents a critical risk that could facilitate unauthorized network access, data exfiltration, or the use of the device as a pivot point for further attacks on the internal network.

Remediation

Immediate Action: Since no specific patch version is currently identified, contact Tenda support or monitor the official Tenda security portal for firmware updates addressing this flaw.

Proactive Monitoring: Review system logs for unusual process execution or unauthorized configuration changes within the Network Configuration Management module.

Compensating Controls: Restrict administrative access to the management interface to trusted IP addresses only, and employ a network firewall to block unauthorized remote access to the device management ports.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Due to the critical nature of this OS command injection vulnerability, organizations using Tenda CP3 hardware must prioritize the identification and isolation of affected units. Until a vendor-supplied patch is verified and deployed, restrict administrative access to the device management interface to mitigate the risk of remote exploitation.

More Tenda CVEs all →

Sources

Originally found and disclosed by FengZi (VulDB User), with VulDB Vulnerability Moderation Team (coordinator), per the CVE Program record.