Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-86167: Tenda HG10 allows remote command execution
CVE-2026-86167 · published 1 month ago
Summary
The Tenda HG10 router can be tricked into running any command on its operating system by sending a specially crafted request to its web interface. This means an attacker could take control of the device from anywhere on the internet. Apply the vendor's security update or disable remote access to the affected web page until a patch is installed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| tenda | hg10 | 300001138 |
Original advisory text
Tenda HG10 Boa formgponConf os command injection
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
8.6
High
Type
CWE-78OS Command Injection
CWE-77Command Injection
Timeline
Published6 Sep 2026
Updated2 Oct 2026
First seen6 Sep 2026
Track software like this
Free during beta