SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-86149

CRITICAL · CVSS 9.1 EPSS 2.04%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A critical vulnerability exists in Tenda CP3 version 27.5.57.101, allowing remote attackers to exploit improper handling of the argument interface_name/host in the NetCheckPing function, leading to OS command injection. This flaw poses a significant risk as it can be exploited without authentication, potentially compromising system integrity and confidentiality. Organizations using this device should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-86149
Severity
CRITICAL
CVSS
9.1
EPSS
2.04%

Original NVD Description

A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.