Description
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.
Published: 2026-09-06
Score: 10 Critical
EPSS: 2.9% Low
KEV: No
Impact: Remote OS Command Injection
Action: Apply Patch
AI Analysis

Impact

A flaw in the CAutoAddWifi::ThreadProc function of the Kylin component allows an attacker to inject operating‑system commands. The injection can enable arbitrary command execution on the router’s firmware, potentially granting full control over the device. This vulnerability directly compromises confidentiality, integrity, and availability of the network infrastructure.

Affected Systems

The vulnerability affects Tenda CP3 routers running firmware version 27.5.57.101. Devices of this model are shipped with the vulnerable AutoAddWifi feature built into the router’s management interface.

Risk and Exploitability

The CVSS score of 10 signifies a critical impact, and the EPSS score of 3% indicates a moderate likelihood of exploitation, though the high severity still indicates significant risk. The flaw can be triggered remotely—likely through the router’s web interface or network management protocols—and a successful exploitation would allow an attacker to execute arbitrary commands on the device. The vulnerability is not yet listed in CISA’s KEV catalog, but its criticality warrants immediate attention.

Generated by OpenCVE AI on September 25, 2026 at 00:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to a version that contains the fix for the AutoAddWifi command injection vulnerability.
  • Disable the AutoAddWifi feature in the router’s settings if the firmware allows it, removing the attack surface.
  • Restrict management interface access to trusted IP ranges, enforce strong authentication, and monitor for suspicious command execution traffic.

Generated by OpenCVE AI on September 25, 2026 at 00:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 06 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda cp3
Vendors & Products Tenda cp3

Sun, 06 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.
Title Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection
First Time appeared Tenda
Tenda cp3 Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:tenda:cp3_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda cp3 Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 10, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-10T18:06:27.153Z

Reserved: 2026-09-05T07:40:31.001Z

Link: CVE-2026-86152

cve-icon Vulnrichment

Updated: 2026-09-10T18:06:23.784Z

cve-icon NVD

Status : Deferred

Published: 2026-09-06T02:17:19.370

Modified: 2026-09-10T19:17:36.807

Link: CVE-2026-86152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T00:45:17Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')