Impact
The vulnerability allows an attacker to execute arbitrary operating-system commands on devices running Tenda CP3 firmware 27.5.57.101 via the sub_2F77E8 function in Apis/system.c. This weakness is classified as CWE-77 and CWE-78 (OS command injection). The description does not specify additional consequences beyond command execution.
Affected Systems
The vulnerability impacts devices running Tenda CP3 firmware version 27.5.57.101. No other Tenda products or versions are listed as affected.
Risk and Exploitability
The CVSS base score of 9.4 classifies the issue as critical. The EPSS score is 2%, and the vulnerability is not listed in the CISA KEV catalog. The description indicates that the command injection can be triggered remotely, implying high exploitability. The attack can be carried out through the Network Configuration Management interface, according to the supplied information.
OpenCVE Enrichment