CVE-2026-86150Medium· 4.1▾ SunlitA security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86153Critical· 9.1A vulnerability has been found in Tenda CP3 27.5.57.101
CVE-2026-86152Critical· 10.0A flaw has been found in Tenda CP3 27.5.57.101
CVE-2026-86151Critical· 9.1A vulnerability was detected in Tenda CP3 27.5.57.101
CVE-2026-86149Critical· 9.1A weakness has been identified in Tenda CP3 27.5.57.101
CVE-2026-86148Critical· 9.1A security flaw has been discovered in Tenda CP3 27.5.57.101
CVE-2026-90688Medium· 6.5A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC