Description
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Published: 2026-09-06
Score: 9.4 Critical
EPSS: 2.7% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Affected Tenda HG10 firmware 300001138 includes a Boa web‑based management interface. The formgponConf endpoint accepts an fmgpon_loid parameter that is insufficiently validated, allowing an attacker to inject arbitrary operating‑system commands. If exploited, the attacker can run any command on the device, gain full control, and potentially launch further attacks on the local network.

Affected Systems

Devices built on the Tenda HG10 platform, specifically firmware version 300001138, are impacted. The vulnerability resides in the Boa component located at /boaform/admin/formgponConf and targets routers that expose the Boa management interface over the network.

Risk and Exploitability

The CVSS score of 9.4 denotes a critical severity, and the attack vector can be exercised remotely via the web interface. The EPSS score of 3% indicates a low but nonzero exploitation probability, while the existence of published exploits indicates a high likelihood of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog, but its public exploit status and lack of available mitigations for unpatched devices elevate the risk. A malicious actor who can reach the device may obtain unrestricted control over the system’s operating system.

Generated by OpenCVE AI on September 25, 2026 at 00:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Tenda HG10 firmware that incorporates the vendor’s fix for the formgponConf command injection.
  • If a firmware update is not immediately available, block or restrict access to the /boaform/admin/formgponConf endpoint, effectively disabling the vulnerable Boa service.
  • Apply network segmentation and firewall rules to prevent external exposure of the router’s web interface, limiting the attack surface.

Generated by OpenCVE AI on September 25, 2026 at 00:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 06 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Tenda hg10
Vendors & Products Tenda hg10

Sun, 06 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Title Tenda HG10 Boa formgponConf os command injection
First Time appeared Tenda
Tenda hg10 Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:tenda:hg10_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda hg10 Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Tenda Hg10 Hg10 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-08T17:46:03.504Z

Reserved: 2026-09-05T10:32:11.111Z

Link: CVE-2026-86167

cve-icon Vulnrichment

Updated: 2026-09-08T17:45:58.591Z

cve-icon NVD

Status : Deferred

Published: 2026-09-06T05:16:50.477

Modified: 2026-09-08T18:21:15.533

Link: CVE-2026-86167

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T00:45:17Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')