CVE-2026-38065: Command Injection
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function actionimsonwithapn via the imsapn parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If the device supports disabling IMS or APN auto-configuration, disable the IMS feature and/or any automatic APN configuration (ims_apn) in the device administration interface to remove the vulnerable code path (action_ims_on_with_apn) from use.
Tenda 5G03 firmware V05.03.02.04 IMS / APN handling (ims_apn) = disabled (if not required) - Compensating control
Limit access to the device management interfaces for Tenda 5G03 V05.03.02.04: disable remote administration, restrict management ports to trusted IPs via firewall/ACL, place the device on a segmented management network, and block or filter access to endpoints that accept the ims_apn parameter until a vendor patch is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-38065?
CVE-2026-38065 has a critical severity rating with a CVSS score of 9.8.
How do I fix CVE-2026-38065?
To fix CVE-2026-38065, update the Tenda 5G03 firmware to the latest version provided by the vendor.
What type of vulnerability is identified in CVE-2026-38065?
CVE-2026-38065 is a command injection vulnerability affecting the Tenda 5G03 router.
What hardware is impacted by CVE-2026-38065?
CVE-2026-38065 specifically affects the Tenda 5G03 model running firmware version V05.03.02.04.
What can attackers do with CVE-2026-38065?
Attackers exploiting CVE-2026-38065 can potentially execute arbitrary commands on the device due to command injection weaknesses.