Description
A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boaform/formTracert. Executing a manipulation of the argument datasize can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
Timeline
| 2026-04-26: | Advisory disclosed |
| 2026-04-26: | VulDB entry created |
| 2026-04-26: | VulDB entry last update |
Credits
2er00ne (VulDB User)
References
vuldb.com/vuln/359759 (VDB-359759 | Tenda HG3 formTracert command injection)
vuldb.com/vuln/359759/cti (VDB-359759 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/802079 (Submit #802079 | Tenda HG3 N300 Wi-Fi xPON ONT HARD_VERSION=V2.0 , Version: 300003070 Remote code execution)
www.notion.so/33e0c75766a880488924cf24523acf6c
www.tenda.com.cn/