A flaw has been found in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. This affects the function system of the file /boaform/formSysCmd. This manipulation of the argument sysCmd causes command injection. The attack may be initiated remotely. The exploit has been published and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/HG10/formSysCmd-sysCmd-command.md | Exploit Third Party Advisory |
| https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/HG10/formSysCmd-sysCmd-command.md#poc | Exploit |
| https://vuldb.com/?ctiid.343484 | Permissions Required VDB Entry |
| https://vuldb.com/?id.343484 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.741425 | Third Party Advisory VDB Entry |
| https://www.tenda.com.cn/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-01-30 17:16
Updated : 2026-02-10 14:34
NVD link : CVE-2026-1690
Mitre link : CVE-2026-1690
CVE.ORG link : CVE-2026-1690
JSON object : View
Products Affected
tenda
- hg10
- hg10_firmware
