Junglewise Threat Intelligence

CVE-2026-86151: Tenda CP3 OS command injection in Network Configuration Management

CVE-2026-86151 · Severity: critical · CVSS 9.1 · Published 2026-09-06

Executive brief

The Tenda CP3 network device contains a command injection vulnerability in its Network Configuration Management component that allows remote attackers to execute arbitrary operating system commands. This could enable an attacker to take full control of the device, access sensitive network data, or use it as a foothold to attack other systems on the network.

Technical details

The vulnerability exists in function sub_2F77E8 within Apis/system.c of the Tenda CP3 Network Configuration Management component. It is an OS command injection flaw that arises from insufficient input sanitization when processing network configuration parameters. The vulnerability is remotely exploitable without requiring authentication or user interaction. A successful exploit allows arbitrary command execution with device privileges, potentially leading to full system compromise, data exfiltration, or lateral movement within the network. Patches for version 27.5.57.101 should be available from Tenda.

Affected products

  • Tenda CP3 27.5.57.101

Timeline

  • 2026-09-06: disclosed

References

Related threats