A reportedly remotely exploitable improper privilege management vulnerability in the Tenda CP3 camera's redirect handling has been assigned a CVSS 3.1 score of 9.1 (Critical) by the reporting CNA.
What Is It
CVE-2026-86153 is described as an improper privilege management vulnerability (CWE-266, CWE-269) in Tenda CP3 firmware version 27.5.57.101. According to the record, the flaw resides in the CRedirServer::SetRedirectEnable function of the file Functions/Redirect.cpp, and manipulation of this function is said to lead to improper privilege management, with remote exploitation reported as possible.
These root-cause and exploitability details come from the submitter-sourced VulDB entry and have not yet been independently corroborated. The CVE record was published on 2026-09-06 by VulDB ([email protected]) and currently carries a vulnerability status of "Received," meaning NVD analysis is still pending; the technical characterization above may change as that analysis proceeds.
Why It Matters
If the record holds up, the issue would be significant: it is rated CRITICAL under both CVSS 3.1 (9.1) and CVSS 4.0 (9.4). The CVSS 3.1 vector, AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, describes an attack that is reachable over the network with low complexity and no user interaction, producing high confidentiality, integrity, and availability impact. Notably, the scope is CHANGED, meaning successful exploitation would affect resources beyond the vulnerable component itself; the CVSS 4.0 scoring reflects this with HIGH subsequent-system impact across all three dimensions.
These scores are the CNA's own assessment and have not been validated by NVD. The one mitigating factor in the vector is that high privileges are required (PR:H), which would mean an attacker needs existing privileged access rather than being able to strike anonymously from the internet. The legacy CVSS 2.0 scoring is consistent with this, listing authentication as MULTIPLE for a base score of 8.3.
No public proof-of-concept or exploitation activity is referenced in the supplied material, so the practical difficulty of reaching the affected function remains unestablished.
What's Vulnerable
- Vendor: Tenda
- Product: CP3
- Affected version: 27.5.57.101
- CPE:
cpe:2.3:o:tenda:cp3_firmware:*:*:*:*:*:*:*:*
No other versions or products are listed as affected in the supplied record. Because the record is unanalyzed, the affected-version list should be treated as provisional rather than exhaustive.
Patch Status
No CISA KEV entry was supplied for CVE-2026-86153, so there is no confirmation of active exploitation and no KEV-mandated remediation deadline or required action. The supplied source material also lists no vendor advisory, patch, or fixed version; the only vendor reference is Tenda's main website. Exploit maturity in the CVSS 4.0 vector is NOT_DEFINED.
Absent a vendor fix, defenders running CP3 devices at this firmware level should focus on limiting network reachability of the device management interface and constraining who holds the privileged access the vector requires, while watching for NVD analysis or a Tenda advisory to confirm or revise the above.
Sources
- NVD, CVE-2026-86153 (record published 2026-09-06, sourced from [email protected])
- VulDB, CVE entry: https://vuldb.com/cve/CVE-2026-86153
- VulDB, Vulnerability record 399276: https://vuldb.com/vuln/399276
- VulDB, Threat intelligence view: https://vuldb.com/vuln/399276/cti
- VulDB, Submission 895354: https://vuldb.com/submit/895354
- Tenda: https://www.tenda.com.cn/