


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument…
Published:
26 april 2026 om 22:00:00
Alert date:
27 april 2026 om 13:02:18
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A remote command injection vulnerability (CVE-2026-7119) has been discovered in Tenda HG3 2.0 routers. The vulnerability affects the /boaform/formCountrystr file where manipulation of the countrystr argument allows attackers to execute OS commands remotely. The exploit is publicly available, making this a critical security concern for affected devices. Organizations using Tenda HG3 routers should prioritize patching or implementing mitigations immediately.
Technical details
Mitigation steps:
Affected products:
Tenda HG3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7119
https://vuldb.com/submit/800859
https://vuldb.com/vuln/359719
https://vuldb.com/vuln/359719/cti
https://www.notion.so/Tenda-HG3-1-33d0c75766a8808d8b38e9d090cec7ab
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
