CVE-2026-7119
HIGHCVSS 8.8/10EPSS 3.27%
Last modified
CVE-2026-7119 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. EPSS estimates a 3.27% chance of exploitation in the next 30 days.
Description
A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Hg3 Firmware | 300003070 |
References
- https://vuldb.com/submit/800859Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/359719Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/359719/ctiPermissions Required, VDB Entry
- https://www.notion.so/Tenda-HG3-1-33d0c75766a8808d8b38e9d090cec7abExploit, Third Party Advisory
- https://www.tenda.com.cn/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-7119?
A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.
How severe is CVE-2026-7119?
CVE-2026-7119 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 3.27% probability of exploitation in the next 30 days.
How do I fix CVE-2026-7119?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-71179Dell Update Package Framework, versions prior to 26.07.03, c…7.8
- CVE-2026-7118A security vulnerability has been detected in code-projects …6.3
- CVE-2026-71180Dell Update Package Framework, versions prior to 26.07.03, c…7.8
- CVE-2026-71181Dell Update Package Framework, versions prior to 26.07.03, c…6
- CVE-2026-71182Dell Update Package Framework, versions prior to 26.07.03, c…6
- CVE-2026-71187The Ebyte device relies on client side authentication logic …9.8
- CVE-2026-71190In OpenStack Swift through 2.38.0, the proxy server Accept h…8.7
- CVE-2026-71191In OpenStack Swift through 2.38.0, S3API middleware does not…6
- CVE-2026-71192In OpenStack Swift through 2.38.0, the S3API middleware does…6
- CVE-2026-71193In OpenStack Designate before 22.0.1, zone creation checks (…9.6
- CVE-2026-71194In OpenStack Designate before 22.0.2, the mDNS handler perfo…6.8
- CVE-2026-71198In OpenStack Glance before 32.0.1, the location API does not…7
Are you affected by CVE-2026-7119?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
