Skip to content
CVSS 8.8 · HIGH

CVE-2026-7160

A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boaform/formTracert. Executing a manipulation of the argument datasize can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

View on NVD

Analysis

This vulnerability affects a specific Tenda HG3 router firmware and allows for remote command injection. It is a vendor-specific hardware issue that does not impact the software development stack or general server infrastructure used by the community.

Severity

Score: 8.8(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-74CWE-77

EPSS

Probability of exploitation (next 30 days): 0.0097 (1.0%)
Percentile: 76.7%
EPSS: 2026-05-06

Affects

tenda:hg3_firmwaretenda:hg3

Technical description

A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boaform/formTracert. Executing a manipulation of the argument datasize can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

Published: 4/27/2026, 10:16:18 PM
Last modified: 4/30/2026, 6:23:30 PM

References

HomeEventsBlogResourcesTeam