SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-86151

CRITICAL · CVSS 9.1 EPSS 2.04%

Source: NVD + CISA KEV + EPSS · Published 2026-09-06 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A critical vulnerability in Tenda CP3 firmware version 27.5.57.101 allows for remote OS command injection through the Network Configuration Management component. This flaw could enable an attacker to execute arbitrary commands on the affected device, potentially compromising the entire network. Organizations using this device should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-86151
Severity
CRITICAL
CVSS
9.1
EPSS
2.04%

Original NVD Description

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.