top of page
perceptive_background_267k.jpg

A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formgponConf. Th…

Published:

26 April 2026 at 22:00:00

Alert date:

27 April 2026 at 19:18:12

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure

A critical security vulnerability has been discovered in Tenda HG3 2.0 router firmware version 300003070. The flaw affects the formgponConf function in the /boaform/admin/formgponConf file, where manipulation of the fmgpon_loid argument leads to OS command injection. This vulnerability can be exploited remotely by attackers to execute arbitrary system commands on the affected device. The exploit code has been publicly released, significantly increasing the risk of active exploitation. Organizations using affected Tenda HG3 routers should immediately apply security updates or implement network-level protections to prevent remote exploitation of this command injection flaw.

Technical details

Mitigation steps:

Affected products:

Tenda HG3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page