← Terug naar overzicht

A critical OS command injection vulnerability has been identified in Tenda HG10 firmware version 300001138. The vulnerability resides in the formgponConf function within the /boaform/admin/formgponConf file of the Boa web server component. An attacker can manipulate the fmgpon_loid argument to inject and execute arbitrary OS commands. The vulnerability is remotely exploitable without physical access to the device. A public exploit is already available, increasing the risk of active exploitation in the wild. The affected device is a home gateway/router product from Tenda, a widely used networking hardware vendor. This type of vulnerability in IoT/networking devices poses significant risks to home and small business networks. Users of the affected firmware version should apply patches or mitigations as soon as they become available.

Affected products

  • Tenda HG10 300001138

Related CVE's

  • CVE-2026-86167

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities