EXPOSURES › CVE-2026-86151
CVE-2026-86151
CRITICALTenda CP3 firmware 27.5.57.101 allows remote OS command injection via network configuration management.
A remote OS command injection vulnerability in Tenda CP3 firmware enables attackers to execute arbitrary commands on the device, posing a severe risk to network infrastructure. DIB organizations must ensure all network hardware is patched and monitored for exploitation, as this type of vulnerability can lead to full device compromise and lateral movement. The vendor has not yet released a patch, and the vulnerability is not currently in the KEV database, but its critical severity warrants immediate attention.
Shame score — A critical remote OS command injection vulnerability in network hardware that allows arbitrary code execution is a severe, avoidable failure that could lead to full device compromise and network infiltration.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.