CVE-2026-86150: Tenda CP3

Medium severity, CVSS 4.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

Affected products

  • Tenda CP3: version 27.5.57.101 only

Published 2026-09-05. Last modified 2026-09-08.