CVE-2026-86167

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-06 05:16

Updated : 2026-09-08 18:21


NVD link : CVE-2026-86167

Mitre link : CVE-2026-86167

CVE.ORG link : CVE-2026-86167


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')