CVE-2026-86152Critical· 10.0▾ MidnightA flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The at…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
1.9%
Last analysed / modified upstream
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86151Critical· 9.1A vulnerability was detected in Tenda CP3 27.5.57.101
CVE-2026-86149Critical· 9.1A weakness has been identified in Tenda CP3 27.5.57.101
CVE-2026-86148Critical· 9.1A security flaw has been discovered in Tenda CP3 27.5.57.101
CVE-2026-8265Medium· 4.7A security vulnerability has been detected in Tenda AC6 15.03.06.23
CVE-2026-8264Medium· 6.3A weakness has been identified in Tenda AC6 15.03.06.23
CVE-2026-8259Medium· 4.7A vulnerability has been found in Tenda AC6 2.0/15.03.06.23