Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-86148

CRITICAL NVD
CVSS Score 9.1
Severity CRITICAL
Published Sep 05, 2026
Vendor unknown

Description

A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

References