Tenda · Cp3 · CVE-2026-86152
**Name of the Vulnerable Software and Affected Versions**
Tenda CP3 version 27.5.57.101
**Description**
A flaw in the Kylin component allows for remote OS command injection. The issue exists within the `CAutoAddWifi::ThreadProc()` function located in the Functions/AutoAddWifi.cpp file.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.