PT-2026-49294 · Tenda · 5G03

·

CVE-2026-38063

·

Published

2026-06-15

·

Updated

2026-06-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda 5G03 version V05.03.02.04 (Version 1.0)
Description Command injection is possible in the action radio on with ia apn() function through the ia parameter. Command injection is a flaw that allows an attacker to execute arbitrary operating system commands on the target machine.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the action radio on with ia apn() function or avoid using the ia parameter.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-38063

Affected Products

5G03