EXPOSURES › CVE-2026-86167
CVE-2026-86167
CRITICALTenda HG10 router allows remote OS command injection via unpatched Boa component.
The Tenda HG10 router's Boa component permits remote OS command injection through the formgponConf function, enabling attackers to execute arbitrary commands on the device. DIB organizations must treat such IoT hardware as high-risk supply-chain vectors; unpatched command injection in network gear can pivot into lateral movement or ransomware staging. Organizations should enforce strict network segmentation for IoT and prioritize patching or replacement of affected hardware.
Shame score — A critical CVSS 9.9 command injection flaw in consumer IoT hardware remained unpatched and publicly exploitable, exposing DIB networks to remote code execution via a widely deployed device.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.