CVE-2026-86153
- EPSS 0.39%
- Veröffentlicht 06.09.2026 01:45:15
- Zuletzt bearbeitet 08.09.2026 18:21:15
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possi...
- EPSS 1.86%
- Veröffentlicht 06.09.2026 01:30:10
- Zuletzt bearbeitet 10.09.2026 19:17:36
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be l...
CVE-2026-86151
- EPSS 2.04%
- Veröffentlicht 05.09.2026 23:45:09
- Zuletzt bearbeitet 11.09.2026 21:17:33
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack ...
CVE-2026-86150
- EPSS 0.22%
- Veröffentlicht 05.09.2026 23:17:41
- Zuletzt bearbeitet 08.09.2026 14:17:30
A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched rem...
CVE-2026-86149
- EPSS 2.04%
- Veröffentlicht 05.09.2026 22:00:09
- Zuletzt bearbeitet 08.09.2026 19:20:09
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remot...
CVE-2026-86148
- EPSS 2.47%
- Veröffentlicht 05.09.2026 21:45:09
- Zuletzt bearbeitet 08.09.2026 18:21:15
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is po...
CVE-2026-19749
- EPSS 0.4%
- Veröffentlicht 13.08.2026 20:45:09
- Zuletzt bearbeitet 18.08.2026 02:17:25
A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results ...
CVE-2026-19748
- EPSS 0.31%
- Veröffentlicht 13.08.2026 20:15:10
- Zuletzt bearbeitet 14.08.2026 19:09:39
A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin ...
- EPSS 2.36%
- Veröffentlicht 13.08.2026 19:45:09
- Zuletzt bearbeitet 14.08.2026 19:09:39
A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes comman...
CVE-2026-51603
- EPSS 0.41%
- Veröffentlicht 09.07.2026 17:17:00
- Zuletzt bearbeitet 10.07.2026 17:41:47
A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted second SETUP request. After completing the OPTIONS, DESCRIBE,...