ZeroHour

CVE-2026-86167

OS Command Injection in Tenda HG10 GPON ONT web interface (Boa)

CVSS 4.0
8.6 high
EPSS
2%p75
Published
()
Modified
AI analysis

CVE-2026-86167 is an OS command injection flaw (CWE-77/CWE-78) in the formgponConf handler at /boaform/admin/formgponConf, which is served by the Boa embedded web server on Tenda HG10 GPON fiber terminals (build/version 300001138). An authenticated remote user can inject commands through the fmgpon_loid (Logical ONT ID) parameter, which the handler passes to the operating system without proper sanitization, causing arbitrary commands to execute on the device. Successful exploitation gives the attacker control of the ONT at the OS level, with high-rated confidentiality, integrity, and availability impact in CVSS 4.0 (8.6, High), including the ability to alter device configuration, disrupt fiber service, or pivot into the subscriber's local network. Affected parties are operators or subscribers of Tenda HG10 units whose Boa admin interface is reachable (over the LAN, or over the WAN where remote management is enabled), and exploitation requires valid low-privilege credentials. The advisory states that a public exploit exists and may be used, though no formal PoC is cataloged; the flaw is not yet in CISA KEV, and EPSS estimates a 1.6% (75th percentile) chance of exploitation within 30 days.

What to do: Contact Tenda or your internet provider for patched HG10 firmware, since the advisory does not specify a fixed version. Until patched, restrict exposure of the device's admin interface — disable WAN-side/remote management and limit access to trusted LAN hosts — and audit affected devices for unexpected configuration changes or signs of command execution via the formgponConf endpoint. Given the publicly available exploit and moderately elevated EPSS, prioritize devices exposed to untrusted networks.

Affected
Tenda HG10 GPON ONT (Boa web server, /boaform/admin/formgponConf)
Estimated exposure
unknown; plausibly tens of thousands of ISP-provisioned units, but no public install-base or internet-scan counts exist for this model — No public scan data or vendor install-base figures are available for the Tenda HG10, and such consumer GPON ONTs are typically bulk-deployed through ISPs whose unit counts are unpublished, so only a qualitative magnitude can be offered.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.