CVE-2026-1689: Tenda HG10 Login formLogin checkUserFromLanOrWan command injection
A vulnerability was detected in Tenda HG10 USHG7HG9HG10re300001138enxpon. The impacted element is the function checkUserFromLanOrWan of the file /boaform/admin/formLogin of the component Login Interface. The manipulation of the argument Host results in command injection. The attack can be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1689?
CVE-2026-1689 is classified as a critical vulnerability due to the possibility of command injection.
How do I fix CVE-2026-1689?
To fix CVE-2026-1689, immediately update the Tenda HG10 firmware to the latest version provided by the manufacturer.
What systems are affected by CVE-2026-1689?
CVE-2026-1689 affects the Tenda HG10 router specifically.
What type of vulnerability is CVE-2026-1689?
CVE-2026-1689 is a command injection vulnerability found in the login functionality of the Tenda HG10 router.
Can CVE-2026-1689 be exploited remotely?
Yes, CVE-2026-1689 can be exploited remotely if the vulnerable Tenda HG10 router is exposed to the internet.