Skip to finding
important · Wi-Fi — Camera

A Tenda CP3 AutoAddWifi path is reported to accept unauthenticated remote command injection, but its reachable endpoint is unknown.

Affects

Tenda CP3, an embedded Wi-Fi security camera running Tenda firmware.

The record names CAutoAddWifi::ThreadProc in the Kylin component as the command-injection sink.

Detail and 2 sources

It does not identify the protocol, endpoint, attacker-controlled field, process privilege, or whether the path is LAN-only, cloud-relayed or internet-exposed.

Chain to watch
Reach the undisclosed network path feeding AutoAddWifi→↓Supply attacker-controlled input to CAutoAddWifi::ThreadProc→↓Trigger the reported operating-system command sink→↓Reachability, the controlled field and execution identity are all unresolved.
Unverified chainObtain the original submission or reproduce the request on firmware 27.5.57.101 while tracing Kylin's sockets and process identity.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 6, 2026