Description
A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2026-04-26: | Advisory disclosed |
| 2026-04-26: | VulDB entry created |
| 2026-04-26: | VulDB entry last update |
Credits
2er00ne (VulDB User)
References
vuldb.com/vuln/359719 (VDB-359719 | Tenda HG3 formCountrystr os command injection)
vuldb.com/vuln/359719/cti (VDB-359719 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/800859 (Submit #800859 | Tenda HG3 N300 Wi-Fi xPON ONT HARD_VERSION=V2.0 , Version: 300003070 Remote code execution)
www.notion.so/Tenda-HG3-1-33d0c75766a8808d8b38e9d090cec7ab
www.tenda.com.cn/