CVE-2026-86152

Summary

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.

Affected Software

VendorProductVersion RangeStatus
TendaCP327.5.57.101affected

Weaknesses

  • CWE-78: OS Command Injection
  • CWE-77: Command Injection

References