High severity8.8NVD Advisory· Published Apr 27, 2026· Updated Apr 30, 2026
CVE-2026-7096
CVE-2026-7096
Description
A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formgponConf. The manipulation of the argument fmgpon_loid results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected products
1- cpe:2.3:o:tenda:hg3_firmware:300003070:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.notion.so/Tenda-HG3-3250c75766a880c7b50fde0466557c5fnvdExploitThird Party Advisory
- vuldb.com/submit/800796nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/359671nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/359671/ctinvdPermissions RequiredVDB Entry
- www.tenda.com.cnnvdProduct
News mentions
0No linked articles in our index yet.