CyberRota Analysis
AI-GeneratedA critical security vulnerability in Tenda CP3 version 27.5.57.101 allows for remote command injection through the SystemAsh function in the Apis/system.c component, specifically by manipulating the AlarmVoiceURL argument. This flaw could enable attackers to execute arbitrary commands on the affected system, posing a significant risk to the integrity and confidentiality of the device. Organizations using this product should prioritize immediate remediation to mitigate potential exploitation.
Original NVD Description
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.