Skip to content
COOEY

EXPOSURES › CVE-2026-86152

CVE-2026-86152

CRITICAL
DETAIL
SourceNVD · cve Published2026-09-06 CVSS10.0 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-86152 ↗
⚡ RCE SHAME 78/100 rceexploited-in-wildunpatched

Tenda CP3 firmware allows remote OS command injection via a flawed WiFi auto-add function.

A remote OS command injection flaw in Tenda CP3 firmware (CVE-2026-86152) allows attackers to execute arbitrary commands on the device. This is critical for DIB organizations because compromised IoT hardware can serve as a foothold for lateral movement, data exfiltration, or ransomware deployment. Organizations must inventory Tenda devices, apply patches immediately, and segment IoT networks to limit blast radius.

Shame score — Remote OS command injection in consumer IoT firmware is a severe, avoidable failure that directly enables full device compromise and network infiltration.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.