PT-2026-29748 · Tenda · Tenda G103

·

CVE-2026-5339

·

Published

2026-04-02

·

Updated

2026-04-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda G103 version 1.0.0.5
Description A flaw exists in the Setting Handler component of the Tenda G103, specifically within the action set net settings function of the gpon.lua file. Manipulation of the authLoid, authLoidPassword, authPassword, authSerialNo, authType, oltType, usVlanId, or usVlanPriority arguments can lead to command injection. This issue is remotely exploitable.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5339

Affected Products

Tenda G103