← Back to overview

A buffer overflow vulnerability has been identified in the Tenda HG10 router (firmware version 300001138). The flaw exists in the formLogin function within the /boaform/formLogin file, served by the Boa Web Server component. An attacker can exploit this vulnerability by manipulating the Username argument to trigger a buffer overflow condition. The attack can be launched remotely without requiring physical access to the device. A public exploit has already been disclosed, increasing the risk of active exploitation. This vulnerability poses a significant threat to users of the affected Tenda HG10 devices. The issue has been catalogued in VulDB and the NVD. No patch or mitigation details are mentioned in the article. Users of the affected device should monitor for vendor advisories from Tenda.

Affected products

  • Tenda HG10 300001138

Related CVE's

  • CVE-2026-85109

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities