Junglewise Threat Intelligence

CVE-2026-86148: Tenda CP3 OS command injection in SystemAsh

CVE-2026-86148 · Severity: critical · CVSS 9.1 · Published 2026-09-05

Executive brief

Tenda CP3 is a network device used for connectivity and system management. A vulnerability in the SystemAsh function allows remote attackers to inject arbitrary operating system commands by manipulating the AlarmVoiceURL parameter, potentially leading to complete device compromise and lateral movement into the network.

Technical details

This is an OS command injection vulnerability in the SystemAsh function of Apis/system.c in the Kylin component. The vulnerability exists because user-supplied input to the AlarmVoiceURL argument is not properly sanitized before being passed to system command execution. An unauthenticated remote attacker can exploit this over the network to execute arbitrary operating system commands with device privileges, achieving full system compromise.

Affected products

  • Tenda CP3 27.5.57.101

Timeline

  • 2026-09-05: disclosed

References

Related threats