Cyber & AI intelligence
Wasteland.
Briefs indexed2452
Issues26
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-86152 2026-09-06

CVE-2026-86152: Critical Unauthenticated OS Command Injection in Tenda CP3 Cameras

"A CVSS 10.0 OS command injection flaw in Tenda CP3 firmware 27.5.57.101 allows remote, unauthenticated attackers to execute commands on affected devices."

A CVSS 10.0 OS command injection flaw in Tenda CP3 firmware 27.5.57.101 allows remote, unauthenticated attackers to execute commands on affected devices.

What Is It

CVE-2026-86152 is an OS command injection vulnerability (CWE-77 / CWE-78) in the Tenda CP3 running firmware version 27.5.57.101. The flaw sits in the CAutoAddWifi::ThreadProc function of the file Functions/AutoAddWifi.cpp, part of the Kylin component. According to the NVD record, manipulation of this element leads to OS command injection, and the attack may be launched remotely.

The issue was published to NVD on 2026-09-06 with a source identifier of [email protected] and currently carries a status of "Received."

Why It Matters

The CVSS v3.1 base score is 10.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Every exploitability factor is set to the worst case: network attack vector, low attack complexity, no privileges required, and no user interaction. Scope is Changed, with High impact to confidentiality, integrity, and availability. CVSS v4.0 scoring from the same CNA also reaches 10.0 CRITICAL, with High subsequent-system impact across all three dimensions; meaning compromise is not expected to stay contained to the vulnerable component.

Practically, an attacker who can reach the device over the network can run operating system commands on it without credentials.

What's Vulnerable

No other versions or products are listed as affected in the NVD record.

Patch Status

CVE-2026-86152 does not appear in CISA's Known Exploited Vulnerabilities catalog as of publication, so there is no KEV-mandated required action or remediation due date attached to it. Exploit maturity in the CVSS v4.0 vector is NOT_DEFINED. Absence from KEV is not evidence that exploitation is not occurring; only that it has not been catalogued.

The NVD record lists no patch, fixed version, or vendor advisory. The only vendor reference in the record is Tenda's main website. Defenders should treat network reachability as the primary control until vendor guidance is confirmed.

Sources