A vulnerability, which was classified as critical, was found in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injection.
This vulnerability was named CVE-2026-7119. The attack may be performed from remote. In addition, an exploit is available.