CVE-2026-86152: Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.
Affected Software
Event History
Frequently Asked Questions
Which deployments are known to be affected?
The affected product identified is Tenda CP3 Kylin version 27.5.57.101. No other versions or configurations are identified in the available data.
Does exploitation require authentication or user interaction?
The supplied severity vector indicates network attack vector, low attack complexity, no privileges required, and no user interaction required. The description states that the attack may be launched remotely.
What is the likely impact if exploitation succeeds?
Successful exploitation can lead to OS command injection. The supplied vector rates confidentiality, integrity, and availability impact as high, with scope changed.