CVE-2026-1689 is a command injection vulnerability found in the login interface of Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon firmware, specifically within the checkUserFromLanOrWan function. This flaw allows remote attackers to execute arbitrary commands by manipulating the 'Host' argument during login. With a CVSS score of 7.3 (HIGH), it poses a significant risk due to its low attack complexity and potential for partial impact on confidentiality, integrity, and availability. While the exploit is publicly available, there is no evidence of active exploitation, nor are there any Metasploit or Nuclei modules, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:tenda:hg10_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.