Tenda Devices Hit by Ten Disclosed Vulnerabilities, Including Critical Flaws
Key findings • Ten vulnerabilities disclosed for Tenda devices between September 5-7, 2026. • Critical flaws include OS command injection, buffer overflows, and improper authentication across…

Key findings
- Ten vulnerabilities disclosed for Tenda devices between September 5-7, 2026.
- Critical flaws include OS command injection, buffer overflows, and improper authentication across multiple models.
- CVE-2026-86152 (CVSS 10.0) is a critical OS command injection vulnerability in Tenda CP3.
- Several exploits are publicly available, increasing the risk of remote exploitation.
- Affected models include Tenda AC9, HG10, and CP3.
On September 7, 2026, a batch of ten vulnerabilities was disclosed for Tenda devices, spanning two days and including critical and high-severity flaws. These vulnerabilities affect various Tenda models, including the AC9, HG10, and CP3, and impact components such as the Web Management interface, Boa Web Server, and system APIs. The disclosures highlight a range of issues, including improper authentication, OS command injection, buffer overflows, and hard-coded credentials, with several exploits publicly available and potentially exploitable remotely.
Several critical vulnerabilities were identified in the Tenda HG10, specifically related to the Boa Web Server. CVE-2026-86167, with a CVSSv3 score of 9.9, allows for OS command injection through manipulation of the fmgpon_loid argument in the formgponConf function. Similarly, CVE-2026-86165 (CVSSv3 9.8) enables buffer overflow via the Keywd/urlFQDN argument in the formURL function. Another critical flaw, CVE-2026-86166 (CVSSv3 8.8), also in the Boa Web Server, leads to a buffer overflow by manipulating the 'if' argument in the formWanRedirect function.
The Tenda CP3 model is also heavily impacted, with multiple critical vulnerabilities disclosed. CVE-2026-86152 (CVSSv3 10.0) is a critical OS command injection flaw within the CAutoAddWifi::ThreadProc function. CVE-2026-86151 (CVSSv3 9.1) involves OS command injection through manipulation of parameters in the system.c file's Network Configuration Management component. CVE-2026-86149 (CVSSv3 9.1) is another OS command injection vulnerability, affecting the Net/NetCheckPing.cpp file. CVE-2026-86148 (CVSSv3 9.1) exploits the SystemAsh function in system.c to achieve OS command injection via the AlarmVoiceURL argument. Additionally, CVE-2026-86153 (CVSSv3 9.1) presents an improper privilege management issue in the CRedirServer::SetRedirectEnable function. A medium-severity vulnerability, CVE-2026-86150 (CVSSv3 4.1), was also found in the CP3, related to hard-coded credentials via the wpa_passphrase argument.
A high-severity flaw, CVE-2026-86300 (CVSSv3 7.3), was identified in the Tenda AC9 model. This vulnerability affects the R7WebsSecurityHandler function within the Web Management component, leading to improper authentication that can be exploited remotely.
The widespread nature of these vulnerabilities across multiple Tenda product lines underscores the need for users to remain vigilant. With several exploits publicly available, the risk of remote exploitation is significant. Users are advised to check for and apply any available firmware updates or security patches released by Tenda to mitigate these risks. The disclosure of these ten vulnerabilities in close succession highlights a significant security event for Tenda device owners.