Tenda G103 Firmware vulnerabilities

5 known vulnerabilities affecting tenda/g103_firmware.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-5339MEDIUMCVSS 5.1v1.0.0.52026-04-02
CVE-2026-5339 [MEDIUM] CWE-74 CVE-2026-5339: A vulnerability was detected in Tenda G103 1.0.0.5. The impacted element is the function action_set_ A vulnerability was detected in Tenda G103 1.0.0.5. The impacted element is the function action_set_net_settings of the file gpon.lua of the component Setting Handler. Performing a manipulation of the argument authLoid/authLoidPassword/authPassword/authSerialNo/authType/oltType/usVlanId/usVlanPriority results in command injection. It is possible to ini
nvd
CVE-2026-5338MEDIUMCVSS 5.1v1.0.0.52026-04-02
CVE-2026-5338 [MEDIUM] CWE-74 CVE-2026-5338: A security vulnerability has been detected in Tenda G103 1.0.0.5. The affected element is the functi A security vulnerability has been detected in Tenda G103 1.0.0.5. The affected element is the function action_set_system_settings of the file system.lua of the component Setting Handler. Such manipulation of the argument lanIp leads to command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
nvd
CVE-2023-33530HIGHCVSS 8.8v1.0.0.52023-06-06
CVE-2023-33530 [HIGH] CWE-77 CVE-2023-33530: There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware ver There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges.
nvd
CVE-2023-27076CRITICALCVSS 9.8v1.0.0.52023-04-10
CVE-2023-27076 [CRITICAL] CWE-78 CVE-2023-27076: Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary c Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter.
nvd
CVE-2023-27079HIGHCVSS 7.5v1.0.052023-03-23
CVE-2023-27079 [HIGH] CWE-77 CVE-2023-27079: Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package
nvd