CVE-2026-86167
OS Command Injection in Tenda HG10 GPON ONT web interface (Boa)
CVE-2026-86167 is an OS command injection flaw (CWE-77/CWE-78) in the formgponConf handler at /boaform/admin/formgponConf, which is served by the Boa embedded web server on Tenda HG10 GPON fiber terminals (build/version 300001138). An authenticated remote user can inject commands through the fmgpon_loid (Logical ONT ID) parameter, which the handler passes to the operating system without proper sanitization, causing arbitrary commands to execute on the device. Successful exploitation gives the attacker control of the ONT at the OS level, with high-rated confidentiality, integrity, and availability impact in CVSS 4.0 (8.6, High), including the ability to alter device configuration, disrupt fiber service, or pivot into the subscriber's local network. Affected parties are operators or subscribers of Tenda HG10 units whose Boa admin interface is reachable (over the LAN, or over the WAN where remote management is enabled), and exploitation requires valid low-privilege credentials. The advisory states that a public exploit exists and may be used, though no formal PoC is cataloged; the flaw is not yet in CISA KEV, and EPSS estimates a 1.6% (75th percentile) chance of exploitation within 30 days.
What to do: Contact Tenda or your internet provider for patched HG10 firmware, since the advisory does not specify a fixed version. Until patched, restrict exposure of the device's admin interface — disable WAN-side/remote management and limit access to trusted LAN hosts — and audit affected devices for unexpected configuration changes or signs of command execution via the formgponConf endpoint. Given the publicly available exploit and moderately elevated EPSS, prioritize devices exposed to untrusted networks.
| Tenda HG10 GPON ONT (Boa web server, /boaform/admin/formgponConf) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.