Impact
A flaw in the formTracert endpoint of the Tenda HG3 router allows an attacker to manipulate the datasize argument and execute arbitrary shell commands. The vulnerability is a classic command injection, enabling the attacker to gain full control of the device. This can lead to additional compromise of the network, data exfiltration, or use of the router as a pivot point.
Affected Systems
The affected equipment is the Tenda HG3 router, specifically firmware version 2.0. The issue resides in the web management interface located at /boaform/formTracert.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS score is not available, but the vulnerability is publicly disclosed and can be exploited remotely. Since it is not listed in the CISA KEV catalog, the risk is largely determined by its high severity and the lack of known mitigations; attackers can readily craft payloads targeting the datasize parameter to achieve remote code execution.
OpenCVE Enrichment