Tenda Cp3 Firmware
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Tenda Cp3 Firmware.
By the Year
In 2026 there have been 6 vulnerabilities in Tenda Cp3 Firmware with an average score of 8.8 out of ten. Last year, in 2025 Cp3 Firmware had 1 security vulnerability published. That is, 5 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.02
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 6 | 8.78 |
| 2025 | 1 | 8.80 |
| 2024 | 0 | 0.00 |
| 2023 | 5 | 8.88 |
It may take a day or so for new Cp3 Firmware vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Tenda Cp3 Firmware Security Vulnerabilities
Tenda CP3 27.5.57.101 Privilege hop via CRedirSrv::SetRedirect (Remote)
CVE-2026-86153
9.4 - Critical
- September 06, 2026
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.
Improper Privilege Management
Remote OS Command Injection in Tenda CP3 27.5.57.101 CAutoAddWifi
CVE-2026-86152
10 - Critical
- September 06, 2026
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.
Shell injection
Tenda CP3 27.5.57.101 CMD Injection via Network Config API
CVE-2026-86151
9.4 - Critical
- September 05, 2026
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.
Shell injection
Hard-coded credentials via hostapd wpa_passphrase in Tenda CP3 27.5.57.101
CVE-2026-86150
5.1 - Medium
- September 05, 2026
A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Use of Hard-coded Credentials
Tenda CP3 27.5.57.101 Remote OS Command Injection via NetCheckPing
CVE-2026-86149
9.4 - Critical
- September 05, 2026
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
Shell injection
OS Command Injection in Tenda CP3 Kylin SystemAsh Before 27.5.57.101
CVE-2026-86148
9.4 - Critical
- September 05, 2026
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.
Shell injection
Tenda CP3 11.10.00.2311090948 Remote Cmd Injection via sub_F3C8C
CVE-2025-5763
8.8 - High
- June 06, 2025
A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this vulnerability is the function sub_F3C8C of the file apollo. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Command Injection
Shenzhen Tenda IP Camera CP3 V11.10.00.2211041355 Firmware Update Lacks Int Check
CVE-2023-30356
7.5 - High
- May 10, 2023
Missing Support for an Integrity Check in Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows attackers to update the device with crafted firmware
Improper Validation of Integrity Check Value
Tenda CP3 UART U-Boot Physical Access Leak Wi-Fi Password
CVE-2023-30354
9.8 - Critical
- May 10, 2023
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.
Cleartext Transmission of Sensitive Information
Unauth RCE via XML in Shenzen Tenda Cam CP3 V11.10.00.2211041355
CVE-2023-30353
9.8 - Critical
- May 10, 2023
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.
Command Injection
Shenzhen Tenda CP3 IP Cam V11.10.00.* has hard-coded default RTSP password
CVE-2023-30352
9.8 - Critical
- May 10, 2023
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.
Use of Hard-coded Credentials
Shenzhen Tenda IP Cam CP3 V11.10.00.2211041355: Hardcoded root TELNET creds
CVE-2023-30351
7.5 - High
- May 10, 2023
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials.
Inadequate Encryption Strength
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Tenda Cp3 Firmware or by Tenda? Click the Watch button to subscribe.