CVE-2026-86151: Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection
Published Sep 5, 2026
·Updated
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.
Affected Software
1 affected component
Tenda CP3 Network Configuration Management=27.5.57.101
Event History
Sep 5, 2026
CVE Published
via MITRE·11:45 PM
Data Sourced
via MITRE·11:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated, highly privileged account?
The CVSS vector specifies PR:H, indicating that high privileges are required. It also specifies AV:N and UI:N, meaning the attack can be conducted over the network without user interaction.
2
What security impact is indicated if the issue is exploited?
The CVSS vector rates confidentiality, integrity, and availability impact as High. It also specifies Scope Changed (S:C).
3
Are versions other than 27.5.57.101 confirmed to be affected?
The available information identifies Tenda CP3 version 27.5.57.101. No other affected or fixed versions are provided.