PT-2026-29748 · Tenda · G103

N0Ps1Ed

·

Published

2026-04-02

·

Updated

2026-04-02

·

CVE-2026-5339

CVSS v3.1

4.7

Medium

AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
A vulnerability was detected in Tenda G103 1.0.0.5. The impacted element is the function action set net settings of the file gpon.lua of the component Setting Handler. Performing a manipulation of the argument authLoid/authLoidPassword/authPassword/authSerialNo/authType/oltType/usVlanId/usVlanPriority results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

Exploit

Fix

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5339

Affected Products

G103