CVE-2026-86148
⛔ criticalSummary
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.
CVSS Score
9.1
Critical
EPSS Score
2.5
Exploit Probability
Published Date
2026-09-05
First Seen: 2026-09-06
📊 Relative Risk Intelligence
This CVE is High Risk - more severe than 87.5% of all 353,175 vulnerabilities in our database.
#43,973
Top 25% most severe
Severity Percentile
Last Modified
2026-09-05
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Vector 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X