


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formgponConf. Th…
Published:
26 april 2026 om 22:00:00
Alert date:
27 april 2026 om 19:18:12
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A critical security vulnerability has been discovered in Tenda HG3 2.0 router firmware version 300003070. The flaw affects the formgponConf function in the /boaform/admin/formgponConf file, where manipulation of the fmgpon_loid argument leads to OS command injection. This vulnerability can be exploited remotely by attackers to execute arbitrary system commands on the affected device. The exploit code has been publicly released, significantly increasing the risk of active exploitation. Organizations using affected Tenda HG3 routers should immediately apply security updates or implement network-level protections to prevent remote exploitation of this command injection flaw.
Technical details
Mitigation steps:
Affected products:
Tenda HG3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7096
https://vuldb.com/submit/800796
https://vuldb.com/vuln/359671
https://vuldb.com/vuln/359671/cti
https://www.notion.so/Tenda-HG3-3250c75766a880c7b50fde0466557c5f
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
