CVE-2026-1689Disclosure(tenda / hg10)

MEDIUMCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch tenda hg10 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function checkUserFromLanOrWan of the file /boaform/admin/formLogin of the component Login Interface. The manipulation of the argument Host results in command injection. The attack can be launched remotely. The exploit is now public and may be used.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hg10
  • hg10_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-01-30); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
hg10hg10_firmware

1 version affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-30: 1Mentions · 2026-05-07: 1Active Exploitation · 2026-05-07: 1Patch / Workaround · 2026-05-07: 1Technical Details · 2026-01-30: 1Technical Details · 2026-05-07: 101-3005-07
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-01-301
Disclosure1
2026-05-071
Active Exploitation1
Full discourse2 posts
  • boarnet@boarnetio
    Active Exploitation

    ⚠️ CRITICAL VULNERABILITY ALERT ⚠️ Botnets are actively exploiting unpatched IoT devices Affected: Tenda, D-Link, & generic routers. CVEs: CVE-2026-1689: Root RCE via Login CVE-2026-2909: Buffer Overflow Patch firmware & disable WAN management! 🛡️ #InfoSec #IoT #RCE

    Post summary

    Alert that botnets are exploiting unpatched IoT routers via CVE-2026-1689 (root RCE) and CVE-2026-2909 (buffer overflow) and advises patching firmware and disabling WAN management.

    000000
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1689 A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function checkUserFromLanOrWan of the file /boaform/admin/fo… https://www.cve.org/CVERecord?id=CVE-2026-1689

    Post summary

    CVE-2026-1689 identifies a vulnerability in Tenda HG10 firmware, specifically affecting the checkUserFromLanOrWan function in /boaform/admin/fo…

    00000257
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendahg10---
OStendahg10_firmware---

Explore more