๐Ÿ” CVE Alert

CVE-2026-7151

HIGH 8.8

Tenda HG3 formIPv6Routing formUploadConfig stack-based overflow

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6Routing. This manipulation of the argument destNet causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

CWE CWE-121 CWE-119
Vendor tenda
Product hg3
Published Apr 27, 2026
Stay Ahead of the Next One

Get instant alerts for tenda hg3

Be the first to know when new high vulnerabilities affecting tenda hg3 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Tenda / HG3
2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/359750 vuldb.com: https://vuldb.com/vuln/359750/cti vuldb.com: https://vuldb.com/submit/802058 notion.so: https://www.notion.so/33e0c75766a88041bd86d3810994a541 tenda.com.cn: https://www.tenda.com.cn/

Credits

๐Ÿ” 2er00ne (VulDB User)