Tenda HG3 Command Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A command injection vulnerability has been identified in the Tenda HG3 router operating system version 2.0. The issue arises in an unknown function of the file '/boaform/formCountrystr', where the 'countrystr' argument can be manipulated to inject operating system commands. This vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected device.

Added: Apr 27, 2026, 12:18 PM
Updated: Apr 27, 2026, 12:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
6.8
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.