PT-2026-5425 · Tenda · Tenda Hg10
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Tenda HG10 US HG7 HG9 HG10re 300001138 en xpon (affected versions not specified)
Description
A flaw exists in the Login Interface component of the software, specifically within the
checkUserFromLanOrWan function located in the /boaform/admin/formLogin file. Manipulation of the Host argument can lead to command injection. This issue is remotely exploitable and the exploit is publicly available.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Hg10