Skip to content
COOEY

EXPOSURES › CVE-2026-86153

CVE-2026-86153

CRITICAL
DETAIL
SourceNVD · cve Published2026-09-06 CVSS9.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-86153 ↗
SHAME 65/100 unpatchedexploited-in-wild

Tenda CP3 firmware 27.5.57.101 contains an unpatched privilege management flaw allowing remote exploitation.

The Tenda CP3 router's CRedirServer::SetRedirectEnable function mishandles privilege escalation, enabling remote attackers to manipulate system privileges. DIB organizations must care because unpatched hardware in OT/ICS environments can lead to network compromise and violate CMMC/NIST 800-171 controls requiring patch management and vulnerability mitigation. Organizations should inventory Tenda CP3 devices, apply firmware updates, and isolate unpatched hardware from classified networks.

Shame score — A critical CVSS 9.1 vulnerability in a consumer-grade router remains unpatched and exploitable remotely, indicating poor vendor patch management and leaving deployed hardware vulnerable to attackers.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.