Post

CVE-2026-86148 - Tenda CP3 Kylin System Command Injection

CVE-2026-86148 - Tenda CP3 Kylin System Command Injection

CVE-2026-86148 - Tenda CP3 Kylin System Command Injection

A security flaw, identified as CVE-2026-86148, has been discovered in Tenda CP3 27.5.57.101. This vulnerability has a CRITICAL CVSS 4.0 score of 9.4. Additionally, it carries a CVSS 3.1 score of 9.1 (CRITICAL), with an Exploitability Score of 2.3 and an Impact Score of 6.0. A CVSS 2.0 score of 8.3 (HIGH) is also associated with this flaw, showing an Exploitability Score of 6.4 and an Impact Score of 10.0. The vulnerability was published on September 5, 2026.

This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in OS command injection. It is possible to launch the attack remotely. The following products are affected by CVE-2026-86148 vulnerability: Tenda CP3. Total Affected Vendor: 1, Products: 1.

To mitigate this vulnerability, users are advised to update Tenda CP3 firmware to patch the OS command injection vulnerability in SystemAsh. This includes updating Tenda CP3 firmware to the latest version and applying vendor security patches when available. Additionally, restricting access to the affected device is recommended.

CVE-2026-86148 is associated with the following CWEs: CWE-77: Improper Neutralization of Special Elements used in a Command (‘Command Injection’), and CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’). Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-86148 weaknesses. Associated CAPECs include: CAPEC-15: Command Delimiters, CAPEC-40: Manipulating Writeable Terminal Devices, CAPEC-43: Exploiting Multiple Input Interpretation Layers, CAPEC-75: Manipulating Writeable Configuration Files, CAPEC-76: Manipulating Web Input to File System Calls, CAPEC-136: LDAP Injection, and CAPEC-183: IMAP/SMTP Command Injection.

For more details, you can read the complete article here: Read full article 🚀

This post is licensed under CC BY 4.0 by the author.