ZeroHour

CVE-2026-86151

large

OS Command Injection in Tenda CP3 Network Configuration Management

CVSS 4.0
9.4 critical
EPSS
2%p80
Published
()
Modified
AI analysis

Tenda CP3 firmware version 27.5.57.101 contains an OS command injection flaw (CWE-77/CWE-78) in the Network Configuration Management component, located in the function sub_2F77E8 of the file Apis/system.c. By remotely manipulating input handled by this function, an attacker can have arbitrary operating-system commands executed on the device. The CVSS 4.0 vector shows the attack is network-based, requires no user interaction and low attack complexity, but does require high privileges — meaning the attacker must already hold an authenticated, privileged session — with high impact on confidentiality, integrity and availability, effectively permitting full device compromise. Owners of Tenda CP3 devices running the affected firmware are in scope. Exploitation has not been confirmed: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS currently estimates only about a 2% chance of exploitation within 30 days (80th percentile).

What to do: Check your CP3's current firmware version and, when Tenda publishes a patched release, upgrade promptly (no fixed version is confirmed in the available data, so monitor Tenda's support/advisory channels). Until patched, reduce exposure by disabling direct port forwarding or UPnP exposure for the camera and restricting remote access to trusted networks or the vendor's cloud app. Devices running firmware 27.5.57.101 should be treated as affected.

Affected
Tenda CP3Firmware 27.5.57.101 (version confirmed in the report; other affected ranges and any fixed version are not specified in the available data)
Estimated exposure
largeplausibly on the order of 100,000+ deployed CP3 devices, though only a subset are likely directly internet-exposed — This is an estimate based on deployment patterns: Tenda is a high-volume consumer IoT vendor and budget smart cameras of this class are widely deployed in homes and small offices, but no public install counts or internet-exposure scan data…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.