EXPOSURES › CVE-2026-86152
CVE-2026-86152
CRITICALTenda CP3 firmware allows remote OS command injection via a flawed WiFi auto-add function.
A remote OS command injection flaw in Tenda CP3 firmware (CVE-2026-86152) allows attackers to execute arbitrary commands on the device. This is critical for DIB organizations because compromised IoT hardware can serve as a foothold for lateral movement, data exfiltration, or ransomware deployment. Organizations must inventory Tenda devices, apply patches immediately, and segment IoT networks to limit blast radius.
Shame score — Remote OS command injection in consumer IoT firmware is a severe, avoidable failure that directly enables full device compromise and network infiltration.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.