Impact
A flaw in the CAutoAddWifi::ThreadProc function of the Kylin component allows an attacker to inject operating‑system commands. The injection can enable arbitrary command execution on the router’s firmware, potentially granting full control over the device. This vulnerability directly compromises confidentiality, integrity, and availability of the network infrastructure.
Affected Systems
The vulnerability affects Tenda CP3 routers running firmware version 27.5.57.101. Devices of this model are shipped with the vulnerable AutoAddWifi feature built into the router’s management interface.
Risk and Exploitability
The CVSS score of 10 signifies a critical impact, and while no EPSS value is reported, the high severity indicates a likely risk of exploitation. The flaw can be triggered remotely—likely through the router’s web interface or network management protocols—and a successful exploitation would allow an attacker to execute arbitrary commands on the device. The vulnerability is not yet listed in CISA’s KEV catalog, but its criticality warrants immediate attention.
OpenCVE Enrichment