CVE-2026-86153: Tenda CP3

Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.

Affected products

  • Tenda CP3: version 27.5.57.101 only

Published 2026-09-06. Last modified 2026-09-08.