SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-86148

CRITICAL · CVSS 9.1 EPSS 2.46%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A critical security vulnerability in Tenda CP3 version 27.5.57.101 allows for remote command injection through the SystemAsh function in the Apis/system.c component, specifically by manipulating the AlarmVoiceURL argument. This flaw could enable attackers to execute arbitrary commands on the affected system, posing a significant risk to the integrity and confidentiality of the device. Organizations using this product should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-86148
Severity
CRITICAL
CVSS
9.1
EPSS
2.46%

Original NVD Description

A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.