CVE-2026-86152

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.

  • Published Sep 6, 2026
  • CVSS 10.0 critical
  • 2.9% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-86152 at the National Vulnerability Database