OS Command Injection Vulnerability in Tenda CP3 by Tenda
CVE-2026-86151

9.4CRITICAL

Key Information:

Vendor

Tenda

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86151?

A significant OS command injection vulnerability has been identified in the Tenda CP3 router's network configuration management component. This issue resides within the function sub_2F77E8 of the Apis/system.c file, enabling attackers to manipulate input and execute commands on the operating system remotely. This could lead to unauthorized access and control of the affected device, posing severe risks to network security. Users are advised to apply the necessary patches and updates to mitigate the threat promptly. For further details, visit the Tenda official website or relevant security advisory sources.

Affected Version(s)

CP3 27.5.57.101

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

FengZi (VulDB User)
VulDB Vulnerability Moderation Team
.