Sceawere
Vulnerability Detail
CVE-2026-86153UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Tenda CP3 Privilege Escalation Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 5h ago
- Vendor
- Tenda
- Product
- CP3
- Attack Type
- Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-09-06T02:17:19.770Z",
"pubdate": "2026-09-06T02:17:19.770Z",
"executiveSummary": "A critical vulnerability identified as improper privilege management exists within the Tenda CP3 firmware version 27.5.57.101.\nThe flaw originates in the CRedirServer::SetRedirectEnable function located within the Redirect.cpp source file.\nThis vulnerability allows for remote exploitation, potentially enabling an attacker to bypass intended access controls and manipulate system redirection settings without sufficient authorization.\nThe vulnerability type, categorized under improper privilege management, indicates a failure in the application's internal permission checks, which may grant unauthenticated or low-privileged users access to sensitive administrative functionality.\nThe impact of this flaw is significant, as it could allow an attacker to alter the device's redirection configuration, potentially leading to traffic interception, man-in-the-middle attacks, or further compromise of the device's integrity.\nThe attack is remotely exploitable, increasing the risk posture for affected Tenda CP3 devices exposed to wide-area networks or untrusted local networks.\nSuccessful exploitation requires the attacker to send specially crafted requests to the vulnerable service, though specific authentication requirements or bypass techniques depend on the internal handling of the target function.",
"technicalDetails": "The vulnerability resides within the CRedirServer::SetRedirectEnable function inside the Redirect.cpp file of the Tenda CP3 firmware version 27.5.57.101.\nThe root cause is a failure in the validation logic responsible for verifying the privilege level of the entity invoking the SetRedirectEnable function. Specifically, the function fails to adequately authenticate the origin of the request or verify that the user session possesses the necessary administrative privileges required to modify redirection configurations.\nThe attack flow initiates when a remote actor sends a specially crafted request—typically via a web-based administrative interface or API endpoint—to the CRedirServer component. The request triggers the SetRedirectEnable function to execute with unintended parameters.\nBecause the function lacks rigorous access control checks, it processes the command as if it originated from an authorized administrator. The function then modifies the internal redirection rules of the device based on the user-supplied input.\nBy manipulating the redirection settings, an attacker can influence the traffic flow of the device. This could be leveraged to redirect internal traffic to an attacker-controlled server, facilitate exfiltration of sensitive information, or bypass security filtering mechanisms implemented on the device.\nThe lack of authentication or privilege enforcement means that the vulnerability can be exploited by an attacker with network reachability to the device's management interface. The payload behavior involves the direct modification of the target device's configuration parameters associated with the redirect service.\nPost-exploitation impact is severe, as the attacker effectively gains the ability to alter the logical flow of network communications routed through the device. This provides a platform for persistent monitoring of user traffic and potential secondary attacks, such as DNS poisoning or unauthorized service proxying, significantly degrading the security posture of the affected networking equipment."
}