← Back to overview

A buffer overflow vulnerability has been identified in the Tenda HG10 router (firmware version 300001138). The vulnerability resides in the formWlanSetup function within the /boaform/formWlanSetup file of the Boa Web Server component. An attacker can manipulate the 'ssid' argument to trigger a buffer overflow condition. The vulnerability is remotely exploitable without requiring physical access to the device. A public exploit has already been disclosed and made available, increasing the risk of active exploitation. The affected product is a consumer-grade IoT/networking device manufactured by Tenda. Given the public availability of the exploit and the remote attack vector, this vulnerability poses a significant risk to users of the affected hardware. Organizations and individuals using the Tenda HG10 should apply patches or mitigations as soon as they become available.

Affected products

  • Tenda HG10 300001138

Related CVE's

  • CVE-2026-85110

Categories

  • Mobile & IoT
  • Network Infrastructure