A CVSS 10.0 OS command injection flaw in Tenda CP3 firmware 27.5.57.101 allows remote, unauthenticated attackers to execute commands on affected devices.
What Is It
CVE-2026-86152 is an OS command injection vulnerability (CWE-77 / CWE-78) in the Tenda CP3 running firmware version 27.5.57.101. The flaw sits in the CAutoAddWifi::ThreadProc function of the file Functions/AutoAddWifi.cpp, part of the Kylin component. According to the NVD record, manipulation of this element leads to OS command injection, and the attack may be launched remotely.
The issue was published to NVD on 2026-09-06 with a source identifier of [email protected] and currently carries a status of "Received."
Why It Matters
The CVSS v3.1 base score is 10.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Every exploitability factor is set to the worst case: network attack vector, low attack complexity, no privileges required, and no user interaction. Scope is Changed, with High impact to confidentiality, integrity, and availability. CVSS v4.0 scoring from the same CNA also reaches 10.0 CRITICAL, with High subsequent-system impact across all three dimensions; meaning compromise is not expected to stay contained to the vulnerable component.
Practically, an attacker who can reach the device over the network can run operating system commands on it without credentials.
What's Vulnerable
- Vendor: Tenda
- Product: CP3
- Affected version: 27.5.57.101 (status: affected)
- Component: Kylin
- CPE:
cpe:2.3:o:tenda:cp3_firmware:*:*:*:*:*:*:*:*
No other versions or products are listed as affected in the NVD record.
Patch Status
CVE-2026-86152 does not appear in CISA's Known Exploited Vulnerabilities catalog as of publication, so there is no KEV-mandated required action or remediation due date attached to it. Exploit maturity in the CVSS v4.0 vector is NOT_DEFINED. Absence from KEV is not evidence that exploitation is not occurring; only that it has not been catalogued.
The NVD record lists no patch, fixed version, or vendor advisory. The only vendor reference in the record is Tenda's main website. Defenders should treat network reachability as the primary control until vendor guidance is confirmed.
Sources
- NVD, CVE-2026-86152: https://nvd.nist.gov/vuln/detail/CVE-2026-86152
- VulDB, CVE-2026-86152: https://vuldb.com/cve/CVE-2026-86152
- VulDB, Vulnerability 399275: https://vuldb.com/vuln/399275
- VulDB, CTI data for 399275: https://vuldb.com/vuln/399275/cti
- VulDB, Submission 895353: https://vuldb.com/submit/895353
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Tenda: https://www.tenda.com.cn/