A critical OS command injection vulnerability has been identified in Tenda HG10 firmware version 300001138. The vulnerability resides in the formgponConf function within the /boaform/admin/formgponConf file of the Boa web server component. An attacker can manipulate the fmgpon_loid argument to inject and execute arbitrary OS commands. The vulnerability is remotely exploitable without physical access to the device. A public exploit is already available, increasing the risk of active exploitation in the wild. The affected device is a home gateway/router product from Tenda, a widely used networking hardware vendor. This type of vulnerability in IoT/networking devices poses significant risks to home and small business networks. Users of the affected firmware version should apply patches or mitigations as soon as they become available.