<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>CP3 (27.5.57.101) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/cp3-27.5.57.101/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 05 Sep 2026 23:34:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/cp3-27.5.57.101/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Injection Vulnerability in Tenda CP3</title><link>https://feed.craftedsignal.io/briefs/2026-09-tenda-cp3-rce/</link><pubDate>Sat, 05 Sep 2026 23:34:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-tenda-cp3-rce/</guid><description>An unauthenticated remote command injection vulnerability in Tenda CP3 firmware version 27.5.57.101 allows attackers to execute arbitrary system commands via the AlarmVoiceURL argument.</description><content:encoded><![CDATA[<p>A critical command injection vulnerability, identified as CVE-2026-86148, has been discovered in the Tenda CP3 security camera firmware version 27.5.57.101. The vulnerability resides in the SystemAsh function within the Apis/system.c file of the Kylin component. An attacker can exploit this flaw by sending a crafted HTTP request that includes malicious shell metacharacters within the AlarmVoiceURL argument. Successful exploitation allows an unauthenticated remote attacker to execute arbitrary operating system commands with the privileges of the underlying firmware process, potentially leading to a full system compromise. This is a network-exploitable vulnerability requiring no user interaction, posing a significant risk to affected devices exposed to the internet.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows full remote code execution on the Tenda CP3 device. If exploited, an attacker could gain persistent access, use the device as a pivot point for further network reconnaissance or lateral movement, intercept traffic, or incorporate the device into a botnet. Given the nature of security cameras, this could also lead to the exposure of sensitive video feeds and private user data.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams managing Tenda CP3 devices:</p>
<ul>
<li>Audit network perimeter logs for HTTP requests directed at Tenda CP3 devices containing suspicious metacharacters (e.g., ;, |, &amp;, $, `) in URI parameters or POST bodies.</li>
<li>Isolate affected Tenda CP3 cameras from the public internet by placing them behind a firewall or VPN, ensuring management interfaces are not exposed.</li>
<li>Contact the vendor for firmware updates addressing the SystemAsh function vulnerability; if no patch is available, restrict access to the device's web management interface to trusted internal IP addresses only.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>firmware-vulnerability</category><category>iot</category><category>network-appliance</category><category>command-injection</category><category>iot-vulnerability</category></item></channel></rss>