CVE-2026-86152: Tenda CP3

Critical severity, CVSS 10.0. EPSS: 2.9% chance of exploitation in the next 30 days.

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.

Affected products

  • Tenda CP3: version 27.5.57.101 only

Published 2026-09-06. Last modified 2026-09-10.