PT-2026-29748 · Tenda · Tenda G103
N0Ps1Ed
·
Published
2026-04-02
·
Updated
2026-04-02
·
CVE-2026-5339
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tenda G103 version 1.0.0.5
Description
A flaw exists in the Setting Handler component of the Tenda G103, specifically within the
action set net settings function of the gpon.lua file. Manipulation of the authLoid, authLoidPassword, authPassword, authSerialNo, authType, oltType, usVlanId, or usVlanPriority arguments can lead to command injection. This issue is remotely exploitable.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda G103