Command Injection Vulnerability in Tenda 5G03 by Tenda
CVE-2026-38062
9.8CRITICAL
What is CVE-2026-38062?
The Tenda 5G03 router, specifically in version V05.03.02.04, is exposed to a command injection vulnerability due to insecure handling of the ratMode parameter in the action_set_rat_mode function. This flaw could allow an attacker to execute arbitrary commands on the device, potentially compromising the network integrity. Addressing this vulnerability is critical for maintaining secure IoT environments.