Sceawere
Vulnerability Detail
CVE-2026-86150UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Tenda CP3 Hard-Coded Credentials
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.1
- Creation Date
- 8h ago
- Vendor
- Tenda
- Product
- CP3
- Attack Type
- Hard-coded Credentials
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.1",
"pubDate": "2026-09-05T23:17:41.337Z",
"pubdate": "2026-09-05T23:17:41.337Z",
"executiveSummary": "A critical security vulnerability has been identified in Tenda CP3 version 27.5.57.101, involving the presence of hard-coded credentials within the system configuration.\nThe vulnerability is specifically associated with the handling of the wpa_passphrase argument within the custom-x/softap/hostapd component.\nThis flaw allows remote attackers to bypass intended authentication mechanisms by leveraging the static, hard-coded passphrase, posing a significant risk to network confidentiality and unauthorized access to the device's soft AP interface.\nBecause the credentials are immutable and embedded within the firmware, the attack surface is exposed to any remote actor capable of reaching the device's wireless interface.\nThe public disclosure of this exploit increases the likelihood of malicious exploitation. Organizations deploying this device must consider the risk of unauthorized network association and potential lateral movement resulting from the compromised wireless security configuration.",
"technicalDetails": "The vulnerability stems from improper credential management within the hostapd configuration process on Tenda CP3 version 27.5.57.101.\nSpecifically, the component identified as custom-x/softap/hostapd contains a hard-coded value utilized for the wpa_passphrase parameter.\nIn the context of the hostapd daemon, which manages IEEE 802.11 access point authentication, the wpa_passphrase serves as the pre-shared key (PSK) for WPA/WPA2 authentication.\nThe root cause is the inclusion of static, predictable authentication material within the binary or configuration templates used by the device during the initialization of the softAP (Software Access Point) mode.\nBecause this passphrase is not dynamically generated or user-configured upon first boot, it remains identical across all affected device deployments, effectively acting as a global backdoor for anyone aware of the hard-coded key.\nThe attack flow involves a remote actor scanning for Tenda CP3 devices that have the softAP feature active. Upon discovery, the attacker initiates a standard WPA handshake.\nInstead of requiring a brute-force attack or credential discovery, the attacker simply supplies the known hard-coded wpa_passphrase to successfully authenticate with the softAP interface.\nOnce the authentication handshake is completed, the attacker is granted access to the wireless network managed by the hostapd instance.\nPost-exploitation impact includes unauthorized entry into the local wireless segment, which may provide further avenues for secondary attacks against internal services, device configuration interfaces, or the interception of unencrypted traffic traversing the softAP.\nThe vulnerability does not require prior knowledge of the user's customized settings, as the flaw resides in the underlying mechanism used by the firmware to provision the softAP service, ensuring the hard-coded credential persists even if other security features are ostensibly enabled."
}