CVE-2026-86152

10.0

Tenda · CP3

A remote OS command injection vulnerability exists in the Tenda CP3 camera within the CAutoAddWifi::ThreadProc function of the Kylin component.

Executive summary

A critical remote OS command injection vulnerability in Tenda CP3 cameras allows unauthenticated attackers to execute arbitrary code with system privileges.

Vulnerability

This flaw is an OS command injection vulnerability (CWE-78) located in the CAutoAddWifi::ThreadProc function of the Kylin component. The vulnerability is remotely exploitable without authentication, allowing an attacker to inject and execute arbitrary system commands.

Business impact

The impact of this vulnerability is severe, as it grants an unauthenticated attacker full control over the affected device. Given the CVSS score of 10.0, this represents a critical risk that could lead to complete system compromise, the potential for lateral movement within the network, and full exposure of video or administrative data handled by the camera.

Remediation

Immediate Action: Contact Tenda support or monitor the official vendor website for a firmware update that addresses this specific vulnerability. If no patch is available, isolate the device from the public internet immediately.

Proactive Monitoring: Monitor network traffic for unusual outbound connections or shell-related activity originating from the camera IP addresses. Review system logs for unexpected execution of commands or process spawning.

Compensating Controls: Place the device behind a strict firewall or within a segmented VLAN that restricts inbound traffic to only necessary ports and trusted sources. Use an Intrusion Prevention System (IPS) to detect and block common command injection patterns targeted at IoT devices.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the critical severity of this vulnerability and the potential for total device takeover, Tenda CP3 users must prioritize the mitigation of this risk. If a firmware update is not currently available, the device should be removed from internet-facing segments until the vendor provides a secure version. Consistent monitoring of vendor security advisories is essential for timely remediation.

More Tenda CVEs all →

Sources

Originally found and disclosed by FengZi (VulDB User), with VulDB Vulnerability Moderation Team (coordinator), per the CVE Program record.