CVE-2026-38061: Command Injection
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function actionsetvolume via the volume parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable remote/web management on the device and restrict administrative access to the local network only.
Tenda 5G03 management interface remote_management = disabled - Compensating control
Restrict access to the device's management ports (HTTP/HTTPS/SSH) at the network perimeter or via ACLs to trusted IP addresses; block management ports from the WAN.
- Compensating control
Deploy network filtering/WAF/IDS rules to detect and block attempts to invoke the action_set_volume function or requests containing a 'volume' parameter with suspicious input (e.g., shell metacharacters).
- Operational
Monitor device logs for calls to action_set_volume and other suspicious activity. If compromise is suspected, perform device recovery (factory reset and reflash firmware) and rotate any credentials that may have been exposed.
- Operational
Monitor vendor advisories and apply any vendor-supplied firmware updates that address this command injection vulnerability as soon as they are released.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-38061?
CVE-2026-38061 has a critical severity rating of 9.8.
What type of vulnerability is identified in CVE-2026-38061?
CVE-2026-38061 is a Command Injection vulnerability in the Tenda 5G03.
How do I fix CVE-2026-38061?
To fix CVE-2026-38061, update the Tenda 5G03 firmware to the latest version provided by the vendor.
What products are affected by CVE-2026-38061?
The affected product for CVE-2026-38061 is the Tenda 5G03 running version V05.03.02.04 (Version 1.0).
What are the potential impacts of CVE-2026-38061?
CVE-2026-38061 could allow an attacker to execute arbitrary commands on the affected device, leading to data compromise and system control.