CVE-2026-7096
8.8Tenda · HG3
Tenda HG3 version 2.0 300003070 is vulnerable to remote OS command injection via the fmgpon_loid argument in the formgponConf function.
Executive summary
A critical OS command injection vulnerability in Tenda HG3 devices allows remote attackers to execute arbitrary commands, posing a significant risk of total system compromise.
Vulnerability
This vulnerability is an OS command injection flaw (CWE-78) located in the /boaform/admin/formgponConf endpoint. An authenticated attacker can trigger the execution of arbitrary system commands by manipulating the fmgpon_loid argument.
Business impact
The ability to perform remote command injection grants an attacker complete control over the affected device. This can lead to unauthorized network access, data interception, and the potential use of the device as a pivot point for further attacks on the internal network. Given the CVSS score of 8.8, this vulnerability is classified as High severity and requires immediate attention to prevent full compromise of the affected hardware.
Remediation
Immediate Action: Since a specific patch version is currently unknown, administrators should restrict network access to the management interface of the HG3 device to trusted internal segments only.
Proactive Monitoring: Monitor system logs for unusual process executions or unexpected changes to configuration files, particularly those originating from the /boaform/admin/ directory.
Compensating Controls: Deploy a Web Application Firewall or network access control list to block unauthorized access to the vulnerable /boaform/admin/formgponConf endpoint.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up provided by the vulnerability researchers.
Analyst recommendation
Given the availability of public proof-of-concept material and the severity of an OS command injection, the risk to Tenda HG3 users is substantial. Organizations must immediately isolate these devices from the public internet and verify if the vendor has provided updated firmware. Until a permanent patch is verified and applied, strict access controls are the most effective method for containing this threat.
More Tenda CVEs
Sources
Originally found and disclosed by 2er00ne (VulDB User), per the CVE Program record.