CVE-2026-7096: Tenda HG3 Firmware
High severity, CVSS 8.8. EPSS: 4.4% chance of exploitation in the next 30 days.
A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formgponConf. The manipulation of the argument fmgpon_loid results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected products
- Tenda HG3 Firmware: version 300003070 only
Published 2026-04-27. Last modified 2026-06-17.