8.8

CVE-2026-5339

Exploit

Tenda G103 Setting gpon.lua action_set_net_settings command injection

A vulnerability was detected in Tenda G103 1.0.0.5. The impacted element is the function action_set_net_settings of the file gpon.lua of the component Setting Handler. Performing a manipulation of the argument authLoid/authLoidPassword/authPassword/authSerialNo/authType/oltType/usVlanId/usVlanPriority results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TendaG103 Firmware Version1.0.0.5
   TendaG103 Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.7% 0.92
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cna@vuldb.com 2 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 4.7 1.2 3.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
cna@vuldb.com 5.8 6.4 6.4
AV:N/AC:L/Au:M/C:P/I:P/A:P
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

https://www.tenda.com.cn/
Product
https://vuldb.com/vuln/354670
Third Party Advisory
VDB Entry
https://vuldb.com/vuln/354670/cti
VDB Entry
Permissions Required
https://vuldb.com/submit/781132
Third Party Advisory
VDB Entry
https://vuldb.com/submit/781133
Third Party Advisory
VDB Entry
https://vuldb.com/submit/781134
Third Party Advisory
VDB Entry
https://vuldb.com/submit/781135
Third Party Advisory
VDB Entry
https://vuldb.com/submit/781142
Third Party Advisory
VDB Entry
https://vuldb.com/submit/781143
Third Party Advisory
VDB Entry
https://vuldb.com/submit/781144
Third Party Advisory
VDB Entry
https://vuldb.com/submit/781145
Third Party Advisory
VDB Entry
https://github.com/ZZ2266/.github.io/tree/main/Tenda%20G103/authLoid
Third Party Advisory
Exploit