Security Advisory

CVE-2026-7096

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-27 06:45:14
Last updated 2026-04-27 11:02:25
Assigner VulDB
CVSS score 8.7
State PUBLISHED

Description

A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formgponConf. The manipulation of the argument fmgpon_loid results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.