CVE-2026-86149
largeAuthenticated OS Command Injection in Tenda CP3 Camera Firmware
CVE-2026-86149 is an operating system command injection flaw in the Tenda CP3 camera (firmware 27.5.57.101), located in the ping-check code in Net/NetCheckPing.cpp. A remote attacker who can reach the camera's management interface and who holds high-privileged (admin-level) credentials can inject arbitrary commands through the 'interface_name' and 'host' arguments, which are passed unsanitized to a shell. Successful exploitation yields full command execution with the privileges of the vulnerable process, which on a device like this typically means complete control of the camera, its configuration, and potentially a foothold into the surrounding network. Only users running the affected Tenda CP3 firmware are known to be impacted. No public proof-of-concept, in-the-wild exploitation, or KEV listing is known; the modest EPSS score of 2.0% (80th percentile) reflects limited near-term exploitation likelihood rather than confirmed safety.
What to do: Check camera firmware versions and apply Tenda's patched firmware as soon as it is released, since no fixed version is identified in the available data. Until then, do not expose the camera's management interface to the WAN (restrict via LAN-only access or firewall rules) and use strong, unique admin credentials, since exploitation requires administrative privileges. Monitor Tenda's advisory channels for confirmation of affected versions and fixes.
| Tenda CP3 | 27.5.57.101 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.