Tenda Vulnerability Vendor: Tenda Product: G3V2 Version: 1.0.0.12(3880) Type: Remote Command Execution Author: Jiaqian Peng Institution: pengjiaqian@iie.ac.cn Vulnerability Description We found a Command Injection vulnerability in Tenda router with firmware which was released recently, allowing remote attackers to execute arbitrary OS commands from a crafted request. Remote Command Execution In binary: In function, is directly passed by the attacker, so we can control the to attack the OS. As you can see here, the initial input will be extracted and cause command injection. PoC We set domain as , and the router will execute it, such as: Result Get a shell!