Skip to finding
important · Firmware — Tenda

A public request demonstrates unauthenticated command injection on the current Tenda HG10 firmware.

Affects

Tenda HG10 GPON optical-network terminals and routers running embedded firmware.

From the LAN, an anonymous caller can place shell syntax in fmgpon_loid; the published benign payload powers off the appliance.

Detail and 2 sources

We do not know whether the route is WAN-reachable or which operating-system identity executes the command.

Chain to watch
Reach the HG10 Boa service→↓Submit shell syntax through fmgpon_loid→↓Determine the executing identity and whether remote management exposes the route→↓WAN exposure and the command’s operating-system identity remain unknown.
Unverified chainTest stock firmware with default and remote-management configurations using a benign identity command.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 7, 2026