Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
tenda-hg10-rce — CVE-2026-1689 Unauthenticated RCE for the Tenda HG10 | Kitploit
Tools/GitHubGitHub/e76f01z/tenda-hg10-rce
ReconnaissanceVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHube76f01z/tenda-hg10-rce

tenda-hg10-rce

CVE-2026-1689 Unauthenticated RCE for the Tenda HG10

View Repository
4 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-1689

Summary

A command injection vulnerability exists in the Tenda HG10 router. It occurs in the formLogin endpoint due to improper handling of the Host parameter.

No authentication credentials are verified as this executes before the check.

User input from the Host header is directly executed as a command without validation:

root@kitploit:~
ifconfig br0 | grep 'inet6' | grep '<user_input>'

Usage

A simple script (exploit.go) is included, which accepts a file containing IP:port/URL pairs for mass exploitation.

Discovery

Over +100k devices are active, and over +15k have already been tested & verified as vulnerable.

FOFA

Download Tool