Skip to content
COOEY

EXPOSURES › CVE-2026-86151

CVE-2026-86151

CRITICAL
DETAIL
SourceNVD · cve Published2026-09-06 CVSS9.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-86151 ↗
⚡ RCE SHAME 78/100 rceunpatchedexploited-in-wild

Tenda CP3 firmware 27.5.57.101 allows remote OS command injection via network configuration management.

A remote OS command injection vulnerability in Tenda CP3 firmware enables attackers to execute arbitrary commands on the device, posing a severe risk to network infrastructure. DIB organizations must ensure all network hardware is patched and monitored for exploitation, as this type of vulnerability can lead to full device compromise and lateral movement. The vendor has not yet released a patch, and the vulnerability is not currently in the KEV database, but its critical severity warrants immediate attention.

Shame score — A critical remote OS command injection vulnerability in network hardware that allows arbitrary code execution is a severe, avoidable failure that could lead to full device compromise and network infiltration.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.