A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-05 22:17
Updated : 2026-09-08 18:21
NVD link : CVE-2026-86148
Mitre link : CVE-2026-86148
CVE.ORG link : CVE-2026-86148
JSON object : View
Products Affected
No product.
