Executive brief
The Tenda 5G03 router, a device used to provide 5G wireless internet connectivity, contains a security flaw in its administrative interface. An attacker with access to the router's management console can execute unauthorized commands on the device. This could allow a malicious actor to take full control of the router, potentially intercepting internet traffic or disrupting network services.
Technical details
An OS command injection vulnerability exists in the Tenda 5G03 router firmware version V05.03.02.04. The flaw is located within the 'action_ims_on_with_apn' function in the '/usr/lib/lua/luci/controller/admin/telephony.lua' script. The 'ims_apn' parameter is processed without sufficient sanitization or validation before being passed to a system shell. An authenticated attacker can exploit this by sending a crafted POST request to the '/cgi-bin/luci/admin/telephony/trigger_set_ims_on_with_apn' endpoint, leading to arbitrary code execution with the privileges of the web service.
Affected products
- Tenda 5G03 V05.03.02.04 (Version 1.0)
Timeline
- 2026-03-16: disclosed: Vulnerability discovered and reported by researcher
- 2026-06-15: advisory: CVE-2026-38065 published