Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-86148: Tenda CP3 router lets remote attackers run commands
CVE-2026-86148 · published 1 month ago
Summary
The Tenda CP3 router (firmware version 27.5.57.101) has a weakness in a function that processes a voice‑alert URL. An attacker can send a specially crafted URL and cause the router to execute arbitrary system commands, potentially taking control of the device. Update the router firmware to the latest version or apply the vendor’s patch as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| tenda | cp3 | 27.5.57.101 |
Original advisory text
Tenda CP3 Kylin system.c SystemAsh os command injection
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-77Command Injection
CWE-78OS Command Injection
Timeline
Published5 Sep 2026
Updated3 Oct 2026
First seen5 Sep 2026
Track software like this
Free during beta