Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mh6w-w5qf-xcmp

Опубликовано: 27 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.4
CVSS3: 8.8

Описание

A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.

A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.

EPSS

Процентиль: 87%
0.03269
Низкий

7.4 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.

CVSS3: 8.8
fstec
3 месяца назад

Уязвимость файла /boaform/formCountrystri микропрограммного обеспечения маршрутизатора Tenda HG3, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 87%
0.03269
Низкий

7.4 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-77