{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-86152/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tenda:cp3:27.5.57.101:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-86148"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CP3 (27.5.57.101)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","firmware-vulnerability","iot","network-appliance","command-injection","iot-vulnerability","cve-2026-86152"],"_cs_type":"advisory","_cs_vendors":["Tenda"],"content_html":"\u003cp\u003eA critical command injection vulnerability, identified as CVE-2026-86148, has been discovered in the Tenda CP3 security camera firmware version 27.5.57.101. The vulnerability resides in the SystemAsh function within the Apis/system.c file of the Kylin component. An attacker can exploit this flaw by sending a crafted HTTP request that includes malicious shell metacharacters within the AlarmVoiceURL argument. Successful exploitation allows an unauthenticated remote attacker to execute arbitrary operating system commands with the privileges of the underlying firmware process, potentially leading to a full system compromise. This is a network-exploitable vulnerability requiring no user interaction, posing a significant risk to affected devices exposed to the internet.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows full remote code execution on the Tenda CP3 device. If exploited, an attacker could gain persistent access, use the device as a pivot point for further network reconnaissance or lateral movement, intercept traffic, or incorporate the device into a botnet. Given the nature of security cameras, this could also lead to the exposure of sensitive video feeds and private user data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams managing Tenda CP3 devices:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit network perimeter logs for HTTP requests directed at Tenda CP3 devices containing suspicious metacharacters (e.g., ;, |, \u0026amp;, $, `) in URI parameters or POST bodies.\u003c/li\u003e\n\u003cli\u003eIsolate affected Tenda CP3 cameras from the public internet by placing them behind a firewall or VPN, ensuring management interfaces are not exposed.\u003c/li\u003e\n\u003cli\u003eContact the vendor for firmware updates addressing the SystemAsh function vulnerability; if no patch is available, restrict access to the device's web management interface to trusted internal IP addresses only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-06T03:35:30Z","date_published":"2026-09-05T23:34:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-tenda-cp3-rce/","summary":"An unauthenticated remote command injection vulnerability in Tenda CP3 firmware version 27.5.57.101 allows attackers to execute arbitrary system commands via the AlarmVoiceURL argument.","title":"Remote Command Injection Vulnerability in Tenda CP3","url":"https://feed.craftedsignal.io/briefs/2026-09-tenda-cp3-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-86152","version":"https://jsonfeed.org/version/1.1"}