Impact
The vulnerability is a command injection flaw in the Boa Webserver component on the Tenda HG10 router. By crafting a malicious value for the serverString argument in the /boaform/formSamba endpoint, an attacker can execute arbitrary operating‑system commands on the device. This flaw can be triggered remotely and does not require local access or authentication, leading to full compromise of the router and the network behind it.
Affected Systems
The affected product is the Tenda HG10 router, specifically the firmware version identified as US_HG7_HG9_HG10re_300001138_en_xpon. No other vendors or product families are listed, and the vulnerability is confined to this specific model.
Risk and Exploitability
The CVSS score of 6.9 indicates high severity, and an EPSS score of 6% suggests a moderate probability of exploitation. The vulnerability is publicly available, and there is no listing in the CISA KEV catalog, so it has not yet been confirmed as an active exploited vulnerability. The attack vector is remote, as the command injection can be exercised over the network by sending HTTP requests to the exposed Boa Webserver interface.
OpenCVE Enrichment