THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86149 (CRITICAL 9.1) — A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.

[NVD] CVE-2026-86149 (CRITICAL 9.1) — A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.

mednvdPublished 2026-09-05

CVE-2026-86149 CVSS: 9.1 CRITICAL Published: 2026-09-05T22:17:18.943

A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86149