Skip to content
Threat Feed
critical advisory

Remote Command Injection Vulnerability in Tenda CP3

An unauthenticated remote command injection vulnerability in Tenda CP3 firmware version 27.5.57.101 allows attackers to execute arbitrary system commands via the AlarmVoiceURL argument.

CVE search metadata

CVE search record: CVE-2026-86148. Severity: critical. CVSS: 9.1. KEV: no. Product: CP3 (27.5.57.101). Brief: Remote Command Injection Vulnerability in Tenda CP3. Brief link: https://feed.craftedsignal.io/briefs/2026-09-tenda-cp3-rce/

What's new

  • 1. added coverage for CP3 (27.5.57.101) Sep 5, 23:34 via nvd

A critical command injection vulnerability, identified as CVE-2026-86148, has been discovered in the Tenda CP3 security camera firmware version 27.5.57.101. The vulnerability resides in the SystemAsh function within the Apis/system.c file of the Kylin component. An attacker can exploit this flaw by sending a crafted HTTP request that includes malicious shell metacharacters within the AlarmVoiceURL argument. Successful exploitation allows an unauthenticated remote attacker to execute arbitrary operating system commands with the privileges of the underlying firmware process, potentially leading to a full system compromise. This is a network-exploitable vulnerability requiring no user interaction, posing a significant risk to affected devices exposed to the internet.

Impact

The vulnerability allows full remote code execution on the Tenda CP3 device. If exploited, an attacker could gain persistent access, use the device as a pivot point for further network reconnaissance or lateral movement, intercept traffic, or incorporate the device into a botnet. Given the nature of security cameras, this could also lead to the exposure of sensitive video feeds and private user data.

Recommendation

Prioritized actions for security teams managing Tenda CP3 devices:

  • Audit network perimeter logs for HTTP requests directed at Tenda CP3 devices containing suspicious metacharacters (e.g., ;, |, &, $, `) in URI parameters or POST bodies.
  • Isolate affected Tenda CP3 cameras from the public internet by placing them behind a firewall or VPN, ensuring management interfaces are not exposed.
  • Contact the vendor for firmware updates addressing the SystemAsh function vulnerability; if no patch is available, restrict access to the device's web management interface to trusted internal IP addresses only.

Immediate actions

Restrict network access to Tenda CP3 management interfaces from external networks

IT Operations 24h

Mitigations

Remove affected cameras from direct public internet exposure

immediate IT Operations

CVE-2026-86148