important · Firmware — Tenda
A public request demonstrates unauthenticated command injection on the current Tenda HG10 firmware.
Affects
Tenda HG10 GPON optical-network terminals and routers running embedded firmware.
From the LAN, an anonymous caller can place shell syntax in fmgpon_loid; the published benign payload powers off the appliance.
Detail and 2 sources
We do not know whether the route is WAN-reachable or which operating-system identity executes the command.
Chain to watch
Reach the HG10 Boa service→↓Submit shell syntax through fmgpon_loid→↓Determine the executing identity and whether remote management exposes the route→↓WAN exposure and the command’s operating-system identity remain unknown.
Unverified chainTest stock firmware with default and remote-management configurations using a benign identity command.