A vulnerability identified as critical has been detected in Tenda 5G03 1.0/05.03.02.04. Affected is the function action_ims_on_with_apn. Performing a manipulation of the argument ims_apn results in command injection.

This vulnerability is known as CVE-2026-38065. Remote exploitation of the attack is possible. No exploit is available.