ZeroHour

CVE-2026-86153

large

Improper Privilege Management in Tenda CP3 Smart Camera

CVSS 4.0
9.4 critical
EPSS
<1%p32
Published
()
Modified
AI analysis

CVE-2026-86153 is an improper privilege management flaw (CWE-266/CWE-269) in the CRedirServer::SetRedirectEnable function of the file Functions/Redirect.cpp in the Tenda CP3 smart camera, reported against firmware version 27.5.57.101. The CVSS 4.0 vector (rated 9.4, critical) indicates the attack is carried out remotely over the network with low complexity and no user interaction, but requires the attacker to already hold high privileges, such as administrative access to the device. By manipulating the redirect-enable function, an attacker with that access achieves high-impact compromise of the camera's confidentiality, integrity, and availability, with system-wide downstream impact. Owners of Tenda CP3 cameras running the reported firmware are affected; the data only confirms version 27.5.57.101, so the full range of vulnerable versions is unconfirmed. Exploitation has not been observed: the issue is not in CISA KEV, no public proof-of-concept exists, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days.

What to do: No fixed firmware version is confirmed in the available data, so check Tenda's official support/download pages for an updated CP3 firmware and apply it as soon as it is released. Until then, avoid exposing the camera's management or redirect service directly to the internet, place the device behind a firewall/NAT, and restrict administrative credentials to trusted users, since exploitation requires high privileges.

Affected
Tenda CP327.5.57.101 (reported version; whether other firmware versions are affected is unconfirmed)
Estimated exposure
largeplausibly hundreds of thousands of CP3 cameras deployed worldwide, with the internet-exposed subset unquantified (estimate) — The Tenda CP3 is a mass-market consumer Wi-Fi camera distributed globally for several years, so cumulative deployments are plausibly in the 100k–1M range, but no public scan counts or vendor install-base figures exist for directly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.

Weakness
CWE-266, CWE-269
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.