Tenda CP3 NetCheckPing.cpp OS Command Injection (CVE-2026-86149)
Release Date: 5th September 2026
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations, System/Network administrators, and general households or small businesses that use the Tenda CP3 Wi-Fi pan/tilt security camera. This alert is intended to be understood by both technical users and general consumers.
What is it?
CVE-2026-86149 is a critical OS command injection vulnerability in the Tenda CP3, the same consumer Wi-Fi pan/tilt security camera addressed in CERTVU Advisory 265 (CVE-2026-86152), Advisory 266 (CVE-2026-86153), and Advisory 267 (CVE-2026-86148) — this is now the fourth critical vulnerability CERTVU has identified on the identical affected firmware build. CERTVU is issuing this as a separate advisory rather than combining it with the three prior ones, since those were already built and delivered before this fourth, distinct vulnerability was researched, and each affects a different function with a different underlying weakness.
What are the systems affected?
The following version(s) are affected:
Tenda CP3 firmware 27.5.57.101 – (Affected)
What does this mean?
Typical attack flow:
- Reach the camera's network-diagnostic function over the network — A remote attacker sends a crafted request to a reachable Tenda CP3 device, supplying a malicious value for the "interface_name" or "host" parameter handled by the device's network connectivity-check (ping) functionality in Net/NetCheckPing.cpp.
- Inject and execute arbitrary operating-system commands — Because the affected function fails to properly sanitise the "interface_name"/"host" parameters before passing them to the underlying operating system, the attacker's injected command is executed directly on the device, giving the attacker arbitrary command execution.
Attack vectors:
- A network-based attack against any Tenda CP3 device reachable by the attacker, whether from the local home/business network or, on a device with remote access or port-forwarding enabled, directly from the internet.
- No user interaction is required (CVSS UI:N).
Successful exploitation may allow attackers to:
- Execute arbitrary commands on the affected camera, gaining full control of the device.
- Access the camera's live video and audio feed, and use the compromised device as a foothold into the wider home or business network it is connected to — the same consequences already described for the companion vulnerabilities in Advisories 265 and 267.
Mitigation process?
CERTVU recommends the following:
-
Restrict Network Access Immediately
Ensure the CP3 is not directly reachable from the internet (disable any remote-access or port-forwarding configuration exposing it), and where possible place it on an isolated guest or IoT-only network segment, separate from computers and other sensitive devices. This is a workaround, not a fix. The underlying command-injection flaw remains present in the firmware, and is the same workaround already recommended for Advisories 265, 266, and 267. -
Treat as Urgent Alongside Companion CVEs
Treat this as urgent alongside its companion vulnerabilities CVE-2026-86152, CVE-2026-86153, and CVE-2026-86148 (Advisories 265-267) on the same device. -
Audit for Tenda CP3 Deployments
Audit the estate/household for Tenda CP3 and similar consumer camera deployments. -
Consider Replacing the Device
Consider replacing the device if it cannot be adequately isolated.
Report suspected compromise to CERTVU at
Reference
- Download advisory (English): CVE-2026-86149_Tenda CP3 NetCheckPing.cpp OS Command Injection