High severity8.8NVD Advisory· Published Apr 27, 2026· Updated Apr 30, 2026
CVE-2026-7160
CVE-2026-7160
Description
A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boaform/formTracert. Executing a manipulation of the argument datasize can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Affected products
1- cpe:2.3:o:tenda:hg3_firmware:300003070:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.notion.so/33e0c75766a880488924cf24523acf6cnvdExploitThird Party Advisory
- vuldb.com/submit/802079nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/359759nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/359759/ctinvdPermissions RequiredVDB Entry
- www.tenda.com.cnnvdProduct
News mentions
0No linked articles in our index yet.