Executive brief
Tenda CP3 is a network device that can be configured and managed remotely. A vulnerability in its WiFi auto-configuration component allows attackers to execute arbitrary operating system commands on the device without authentication, potentially leading to complete device compromise and lateral movement into the network.
Technical details
The vulnerability is an OS command injection flaw in the CAutoAddWifi::ThreadProc function within Functions/AutoAddWifi.cpp of the Kylin component in Tenda CP3. The vulnerable function fails to properly sanitize user-supplied input before passing it to system command execution, allowing an attacker to inject arbitrary shell commands. The attack is remotely exploitable without requiring authentication or user interaction. A successful exploit grants an attacker the ability to execute arbitrary commands with the privileges of the device's system process, potentially enabling full device takeover. Patch status and availability information is not currently specified in available advisories.
Affected products
- Tenda CP3 27.5.57.101
Timeline
- 2026-09-06: disclosed