ZeroHour

CVE-2026-86149

large

Authenticated OS Command Injection in Tenda CP3 Camera Firmware

CVSS 4.0
9.4 critical
EPSS
2%p80
Published
()
Modified
AI analysis

CVE-2026-86149 is an operating system command injection flaw in the Tenda CP3 camera (firmware 27.5.57.101), located in the ping-check code in Net/NetCheckPing.cpp. A remote attacker who can reach the camera's management interface and who holds high-privileged (admin-level) credentials can inject arbitrary commands through the 'interface_name' and 'host' arguments, which are passed unsanitized to a shell. Successful exploitation yields full command execution with the privileges of the vulnerable process, which on a device like this typically means complete control of the camera, its configuration, and potentially a foothold into the surrounding network. Only users running the affected Tenda CP3 firmware are known to be impacted. No public proof-of-concept, in-the-wild exploitation, or KEV listing is known; the modest EPSS score of 2.0% (80th percentile) reflects limited near-term exploitation likelihood rather than confirmed safety.

What to do: Check camera firmware versions and apply Tenda's patched firmware as soon as it is released, since no fixed version is identified in the available data. Until then, do not expose the camera's management interface to the WAN (restrict via LAN-only access or firewall rules) and use strong, unique admin credentials, since exploitation requires administrative privileges. Monitor Tenda's advisory channels for confirmation of affected versions and fixes.

Affected
Tenda CP327.5.57.101
Estimated exposure
largeplausibly on the order of hundreds of thousands of deployed consumer cameras (no authoritative count) — The CP3 is a mass-market budget Wi-Fi camera sold through broad retail and e-commerce channels, so installed base is likely in the hundreds of thousands, though no public scan data or vendor sales figures were available to confirm this.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.