CVE-2026-86153: Tenda CP3 Redirect.cpp SetRedirectEnable privileges management
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
The affected product identified is Tenda CP3 version 27.5.57.101. The available data does not identify other affected versions or configurations.
What level of access does an attacker need?
The severity vector indicates that an attacker requires high privileges, while exploitation can be performed remotely and does not require user interaction. The data does not specify which privileges are needed or how they are obtained.
What impact could successful exploitation have?
The provided severity vector rates confidentiality, integrity, and availability impact as high, with scope changed. This indicates that exploitation may affect resources beyond the initially vulnerable security authority.