There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges.
References
Configurations
Configuration 1 (hide)
| AND |
|
History
09 Jul 2026, 01:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 08:05
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://tenda.com - Not Applicable | |
| References | () https://github.com/D2y6p/CVE/blob/main/tenda/CVE-2023-33530/RCE2/tenda_G103_RCE_2.pdf - Broken Link |
15 Jun 2023, 12:09
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:tenda:g103_firmware:1.0.0.5:*:*:*:*:*:*:* cpe:2.3:h:tenda:g103:-:*:*:*:*:*:*:* |
|
| CWE | CWE-77 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| First Time |
Tenda
Tenda g103 Firmware Tenda g103 |
|
| References | (MISC) https://github.com/D2y6p/CVE/blob/main/tenda/CVE-2023-33530/RCE2/tenda_G103_RCE_2.pdf - Broken Link | |
| References | (MISC) http://tenda.com - Not Applicable |
06 Jun 2023, 13:36
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-06-06 13:15
Updated : 2026-07-09 01:18
NVD link : CVE-2023-33530
Mitre link : CVE-2023-33530
CVE.ORG link : CVE-2023-33530
JSON object : View
Products Affected
tenda
- g103
- g103_firmware
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
