CVE-2026-86149

A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.

  • Published Sep 5, 2026
  • CVSS 9.4 critical
  • 2.9% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-86149 at the National Vulnerability Database