CVE-2026-86153
9.1Tenda · CP3
A privilege management vulnerability in the CRedirServer::SetRedirectEnable function of Tenda CP3 version 27.5.57.101 allows remote attackers to manipulate system privileges.
Executive summary
A critical privilege management flaw in Tenda CP3 version 27.5.57.101 potentially allows remote attackers to gain unauthorized elevated control over the device.
Vulnerability
The vulnerability exists in the CRedirServer::SetRedirectEnable function within Functions/Redirect.cpp. It stems from improper privilege management, which can be exploited by an authenticated attacker with high privileges to perform unauthorized actions.
Business impact
With a CVSS score of 9.1, this vulnerability represents a critical risk to device integrity. An attacker who successfully exploits this flaw can bypass intended access controls, leading to total system compromise, unauthorized data access, and the potential for full control over the router functionality.
Remediation
Immediate Action: Contact Tenda support or monitor the official Tenda website for firmware updates addressing this vulnerability.
Proactive Monitoring: Audit device configurations for unauthorized changes and monitor management interface logs for abnormal activity.
Compensating Controls: Restrict access to the device management interface to known, trusted IP addresses using network-level ACLs.
Exploitation status
Public Exploit Available: Unknown; no confirmed public exploit or weaponized module is currently identified.
Analyst recommendation
Due to the critical severity of this vulnerability, administrators should isolate the Tenda CP3 devices from public-facing networks until a firmware patch is available. Constant vigilance through log monitoring is necessary to detect any attempts to leverage this privilege management flaw.
More Tenda CVEs all →
Sources
Originally found and disclosed by FengZi (VulDB User), with VulDB Vulnerability Moderation Team (coordinator), per the CVE Program record.
- VDB-399276 | Tenda CP3 Redirect.cpp SetRedirectEnable privileges management Vulnerability database entry
- VDB-399276 | CTI Indicators (IOB, IOC, TTP, IOA)
- CVE-2026-86153 | CVE Analysis and Report Third-party advisory
- Submit #895354 | Tenda CP3 V3.2 V27.5.57.101 Improper Access Controls Third-party advisory
- tenda.com.cn