Vulnerability Description
A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Hg3 Firmware | 300003070 |
| Tenda | Hg3 | 2.0 |
Related Weaknesses (CWE)
References
- https://vuldb.com/submit/800859Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359719Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359719/ctiPermissions RequiredVDB Entry
- https://www.notion.so/Tenda-HG3-1-33d0c75766a8808d8b38e9d090cec7abExploitThird Party Advisory
- https://www.tenda.com.cn/Product
FAQ
What is CVE-2026-7119?
CVE-2026-7119 is a vulnerability with a CVSS score of 8.8 (HIGH). A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command inject...
How severe is CVE-2026-7119?
CVE-2026-7119 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-7119?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Hg3 Firmware, Tenda Hg3.