High severity8.8NVD Advisory· Published Apr 27, 2026· Updated Apr 30, 2026
CVE-2026-7119
CVE-2026-7119
Description
A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.
Affected products
1- cpe:2.3:o:tenda:hg3_firmware:300003070:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.notion.so/Tenda-HG3-1-33d0c75766a8808d8b38e9d090cec7abnvdExploitThird Party Advisory
- vuldb.com/submit/800859nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/359719nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/359719/ctinvdPermissions RequiredVDB Entry
- www.tenda.com.cnnvdProduct
News mentions
0No linked articles in our index yet.