CVE-2026-86149 — This manipulation of the argument interface_name/host causes os command injection.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely. CVSSv3.1 9.1 (CRITICAL)