CVE-2026-86152
—OS Command Injection in Tenda CP3 Smart Camera (Kylin component)
CVE-2026-86152 is a critical (CVSS 4.0: 10) OS command injection flaw in Tenda CP3 camera firmware version 27.5.57.101, located in the CAutoAddWifi::ThreadProc function of Functions/AutoAddWifi.cpp within the camera's Kylin component. A manipulation of input handled by this auto-add-WiFi function allows attacker-controlled commands to be executed on the device, and the attack can be launched remotely; the CVSS vector indicates no privileges, no user interaction, and no elevated attack complexity are required, with high impact on confidentiality, integrity, and availability. A successful exploit effectively yields full compromise of the camera, letting an attacker read, modify, or destroy data and take control of the device. Users operating Tenda CP3 cameras on the affected firmware are exposed, particularly units whose network services are reachable from beyond the local network. As of the latest data there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only a 1.9% probability of exploitation within 30 days, so exploitation has not been confirmed in the wild.
What to do: Check your CP3 camera's current firmware version and apply a firmware update from Tenda as soon as a patched release is published (no fixed version is specified in the available data, so monitor Tenda advisories). Until patching is possible, reduce exposure by keeping the camera behind a firewall, removing or limiting WAN-facing port forwarding, and placing IoT devices on a segmented network. Since the flaw sits in the auto-add-WiFi (Kylin) functionality, pay attention to vendor guidance on that feature when re-provisioning or setting up cameras.
| Tenda CP3 smart camera (Kylin component, AutoAddWifi function) | firmware 27.5.57.101 (the only version named in the available data; other versions may also be affected) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.