ZeroHour

CVE-2026-86148

Remote Command Injection in Tenda CP3 Camera via AlarmVoiceURL

CVSS 4.0
9.4 critical
EPSS
2%p84
Published
()
Modified
AI analysis

CVE-2026-86148 is an operating system command injection flaw (CWE-77/CWE-78) in the SystemAsh function of the file Apis/system.c, part of the Kylin component of the Tenda CP3 camera running firmware 27.5.57.101. It is triggered remotely when the AlarmVoiceURL argument is manipulated with crafted input, causing attacker-controlled commands to be executed in the device's OS. The CVSS 4.0 vector indicates high privileges are required (PR:H), meaning an attacker first needs administrative-level access to the device, but successful exploitation yields high impact to confidentiality, integrity, and availability of the camera and potentially subsequent systems. Any deployment of the Tenda CP3 on the affected firmware is exposed, particularly units whose management interface is reachable from the internet. As of this writing there is no public proof of concept, the flaw is not in CISA's KEV, and EPSS assigns a roughly 2.5% probability of exploitation within 30 days.

What to do: Check your CP3 firmware version against 27.5.57.101 and watch Tenda's advisories for a patched release; no fixed version number is provided in the available data. Until updated firmware is available, avoid exposing the camera's management interface directly to the internet and protect administrative credentials, since exploitation requires high-privileged access. Monitor vendor communications for an update addressing the AlarmVoiceURL command injection.

Affected
Tenda CP3 (Kylin component; SystemAsh function in Apis/system.c)27.5.57.101 (as reported; no broader version ranges specified)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.