CVE-2026-7160
8.8Tenda · HG3
Tenda HG3 version 2.0 contains a command injection vulnerability in the formTracert function within the /boaform/formTracert file, which can be triggered via a manipulated datasize argument.
Executive summary
A critical command injection vulnerability in Tenda HG3 version 2.0 allows remote attackers to execute arbitrary system commands, posing a severe risk to device integrity.
Vulnerability
The flaw exists due to improper input validation in the formTracert function, specifically within the datasize argument. An attacker with low privileges can perform remote command injection to execute unauthorized code on the affected device.
Business impact
The ability to execute arbitrary commands remotely grants an attacker full control over the affected Tenda HG3 router. This level of compromise can lead to complete network traffic interception, unauthorized access to internal resources, and the potential for the device to be co-opted into a botnet. Given the CVSS score of 8.8, this vulnerability represents a high-severity risk to operational stability and network security.
Remediation
Immediate Action: As no specific patch version is currently identified, administrators should restrict network access to the management interface of the affected device and monitor for any available firmware updates from the vendor website.
Proactive Monitoring: Implement network traffic analysis to detect unusual outbound connections or suspicious command patterns originating from the router.
Compensating Controls: Deploy a Web Application Firewall or adjust firewall rules to block access to the /boaform/formTracert endpoint from untrusted networks.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the referenced security write-up.
Analyst recommendation
Given the high CVSS score and the existence of a public proof-of-concept, this vulnerability must be treated with urgency. Administrators should isolate the vulnerable Tenda HG3 units from external network exposure until a vendor-supplied firmware update is verified and applied.
More Tenda CVEs
Sources
Originally found and disclosed by 2er00ne (VulDB User), per the CVE Program record.