SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-86152

CRITICAL · CVSS 10 EPSS 1.86%

Source: NVD + CISA KEV + EPSS · Published 2026-09-06 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the Tenda CP3, specifically within the CAutoAddWifi::ThreadProc function, allowing for remote command injection due to improper input validation. This flaw could enable attackers to execute arbitrary operating system commands, potentially compromising the device and its network. Organizations using the affected Tenda CP3 model should prioritize immediate patching to mitigate the risk of exploitation.

CVE
CVE-2026-86152
Severity
CRITICAL
CVSS
10
EPSS
1.86%

Original NVD Description

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.