Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda hg3 Firmware
|
|
| CPEs | cpe:2.3:h:tenda:hg3:2.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:hg3_firmware:300003070:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda hg3 Firmware
|
Tue, 28 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda hg3 |
|
| Vendors & Products |
Tenda
Tenda hg3 |
Mon, 27 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boaform/formTracert. Executing a manipulation of the argument datasize can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. | |
| Title | Tenda HG3 formTracert command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-28T14:35:44.664Z
Reserved: 2026-04-26T20:17:52.059Z
Link: CVE-2026-7160
Updated: 2026-04-28T13:39:59.672Z
Status : Analyzed
Published: 2026-04-27T22:16:18.690
Modified: 2026-04-30T18:23:30.173
Link: CVE-2026-7160
No data.
OpenCVE Enrichment
Updated: 2026-04-28T19:45:07Z