cbcvebase.

Tenda Hg3 vulnerabilities

4 known vulnerabilities affecting tenda/hg3.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4

Vulnerabilities

Page 1 of 1
CVE-2026-7096P2HIGHCVSS 8.8v2.0 3000030702026-04-27
CVE-2026-7096 [HIGH] CWE-77 CVE-2026-7096: A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the funct A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formgponConf. The manipulation of the argument fmgpon_loid results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
nvd
CVE-2026-7119P2HIGHCVSS 8.8v2.02026-04-27
CVE-2026-7119 [HIGH] CWE-77 CVE-2026-7119: A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the fi A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.
nvd
CVE-2026-7160P2HIGHCVSS 8.8v2.02026-04-27
CVE-2026-7160 [HIGH] CWE-74 CVE-2026-7160: A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boaform/formTracert. Executing a manipulation of the argument datasize can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2026-7151P2HIGHCVSS 8.8v2.02026-04-27
CVE-2026-7151 [HIGH] CWE-119 CVE-2026-7151: A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the fi A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6Routing. This manipulation of the argument destNet causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
nvd
Tenda Hg3 vulnerabilities | cvebase