Executive brief
A vulnerability exists in the Tenda G103 GPON terminal, a device used to connect homes and businesses to fiber-optic internet. An attacker can exploit this flaw to take complete control of the device, potentially allowing them to monitor internet traffic, disrupt service, or use the device as a foothold to attack other systems on the local network. This issue is particularly serious because technical details and exploit methods are publicly available.
Technical details
A command injection vulnerability exists in the Tenda G103 firmware version 1.0.0.5 within the 'action_set_net_settings' function of 'gpon.lua'. The root cause is the improper sanitization of several parameters, including 'authLoid', 'authLoidPassword', and 'authSerialNo', which are directly concatenated into system shell commands (such as 'fw_setenv' and 'uci'). An authenticated attacker can use shell metacharacters (e.g., backticks or semicolons) to inject and execute arbitrary commands with root privileges. While some sources categorize this as medium severity due to the requirement for authentication, the impact is a full system compromise. Proof-of-concept exploits are publicly available.
Affected products
- Tenda G103 1.0.0.5
Timeline
- 2026-04-02: disclosed: Initial disclosure via VulDB and NVD
- 2026-04-02: advisory