在 Tenda HG10 型号(产品编号 300001138)中发现一个漏洞。 受影响组件:Boa 组件中 文件里的 函数。 漏洞类型:对参数 的处理不当,导致 操作系统命令注入(OS Command Injection)。 攻击方式:支持远程利用。 风险状况:该漏洞的利用代码已公开,可能被攻击者用于发起攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86152 | 10.0 CRITICAL | Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection |
| CVE-2026-86165 | 9.8 CRITICAL | Tenda HG10 formURL buffer overflow |
| CVE-2026-86153 | 9.1 CRITICAL | Tenda CP3 Redirect.cpp SetRedirectEnable privileges management |
| CVE-2026-86166 | 8.8 HIGH | Tenda HG10 Boa Web Server formWanRedirect buffer overflow |
No comments yet