A critical OS command injection flaw reported in the Tenda CP3 camera's network configuration handler would, according to the CNA-supplied record, allow a remote, authenticated attacker to execute arbitrary commands on the device. The record carries a CVSS v3.1 score of 9.1, though it has not yet been independently analyzed.
What Is It
CVE-2026-86151 is described as an OS command injection vulnerability (CWE-77, CWE-78) in Tenda CP3 firmware version 27.5.57.101. According to the NVD record, the flaw sits in the function sub_2F77E8 in the file Apis/system.c, part of the device's Network Configuration Management component. Manipulating input handled by that function is said to result in OS command injection, and the attack is reported to be initiable remotely.
The issue was assigned by VulDB as the CNA and published on 2026-09-05. As of this writing the NVD entry is still in "Received" status, meaning it has not completed NVD analysis. Every technical detail below therefore reflects the submitter's own assessment rather than independently verified analysis.
Why It Matters
The CVSS v3.1 base score supplied with the record is 9.1 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact. (The source record labels this string with a CVSS:4.0/ prefix, but the metrics it contains, including the scope element S:C, are v3.1 metrics; v4.0 has no scope metric.) A separate CVSS v4.0 secondary score is higher at 9.4 (CRITICAL), with high impact to both the vulnerable system and downstream subsequent systems.
The one mitigating factor is the privilege requirement: both the v3.1 and v4.0 vectors list PR:H (high privileges required), and the CVSS v2 vector specifies multiple-instance authentication. That raises the bar for exploitation. If the reported behavior holds up under analysis, command injection on an embedded camera would convert a management-plane account into full device code execution, and the changed scope rating suggests the submitter judged the blast radius to extend past the camera itself.
There is no CISA KEV entry for this CVE in the supplied data, and exploit maturity in the CVSS v4.0 vector is NOT_DEFINED. Active exploitation is not confirmed.
What's Vulnerable
- Vendor: Tenda
- Product: CP3
- Affected version: firmware 27.5.57.101
- CPE:
cpe:2.3:o:tenda:cp3_firmware:*:*:*:*:*:*:*:* - Component: Network Configuration Management
Patch Status
The supplied source material lists no patch, fixed version, vendor advisory, or required remediation action. The only vendor reference provided is Tenda's main site. Until a fix is confirmed, treat affected CP3 units as exposed and restrict network reachability to their management interfaces.
Sources
- NVD, CVE-2026-86151: https://nvd.nist.gov/vuln/detail/CVE-2026-86151
- VulDB, CVE-2026-86151: https://vuldb.com/cve/CVE-2026-86151
- VulDB, Vulnerability 399274: https://vuldb.com/vuln/399274
- VulDB, CTI details: https://vuldb.com/vuln/399274/cti
- VulDB, Submission 895352: https://vuldb.com/submit/895352
- Tenda: https://www.tenda.com.cn/