EXPOSURES › CVE-2026-86153
CVE-2026-86153
CRITICALTenda CP3 firmware 27.5.57.101 contains an unpatched privilege management flaw allowing remote exploitation.
The Tenda CP3 router's CRedirServer::SetRedirectEnable function mishandles privilege escalation, enabling remote attackers to manipulate system privileges. DIB organizations must care because unpatched hardware in OT/ICS environments can lead to network compromise and violate CMMC/NIST 800-171 controls requiring patch management and vulnerability mitigation. Organizations should inventory Tenda CP3 devices, apply firmware updates, and isolate unpatched hardware from classified networks.
Shame score — A critical CVSS 9.1 vulnerability in a consumer-grade router remains unpatched and exploitable remotely, indicating poor vendor patch management and leaving deployed hardware vulnerable to attackers.
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.