Impact
Affected Tenda HG10 firmware 300001138 includes a Boa web‑based management interface. The formgponConf endpoint accepts an fmgpon_loid parameter that is insufficiently validated, allowing an attacker to inject arbitrary operating‑system commands. If exploited, the attacker can run any command on the device, gain full control, and potentially launch further attacks on the local network.
Affected Systems
Devices built on the Tenda HG10 platform, specifically firmware version 300001138, are impacted. The vulnerability resides in the Boa component located at /boaform/admin/formgponConf and targets routers that expose the Boa management interface over the network.
Risk and Exploitability
The CVSS score of 9.4 denotes a critical severity, and the attack vector can be exercised remotely via the web interface. The EPSS score of 3% indicates a low but nonzero exploitation probability, while the existence of published exploits indicates a high likelihood of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog, but its public exploit status and lack of available mitigations for unpatched devices elevate the risk. A malicious actor who can reach the device may obtain unrestricted control over the system’s operating system.
OpenCVE Enrichment