Security Advisory

CVE-2026-86148

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-05 21:45:09
Last updated 2026-09-08 17:17:22
Assigner VulDB
CVSS score 9.4
State PUBLISHED

Description

A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.