Impact
The vulnerability is an OS command injection flaw in the NetCheckPing.cpp component of the Tenda CP3 router firmware version 27.5.57.101. By manipulating the interface_name/host argument, an attacker can execute arbitrary OS commands when the NetCheckPing interface is invoked. The flaw satisfies CWE‑77 and CWE‑78, and can be used to compromise confidentiality, integrity, and availability of the device and any connected networks.
Affected Systems
Affected devices are Tenda CP3 routers running firmware 27.5.57.101. The precise product is Tenda CP3.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity, and exploitation can occur remotely without authentication. EPSS data is not available, but the absence of a KEV listing does not reduce the urgency. The attack vector is likely a network‑based request that triggers the vulnerable NetCheckPing path, allowing the attacker to control execution of shell commands on the device. Given the high severity and remote nature, the risk is considered high.
OpenCVE Enrichment