CVE-2026-86167: Tenda HG10 Boa formgponConf os command injection
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgponloid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable over the network and requires low privileges. No user interaction is required.
Which systems are identified as affected?
The reported affected product version is Tenda HG10 300001138. The vulnerable functionality is the Boa formgponConf endpoint at /boaform/admin/formgponConf.
How urgent is remediation?
A public exploit is available and may be used. The reported impact includes compromise of confidentiality, integrity, and availability, so exposed affected devices should be prioritized.