← Back to overview

A buffer overflow vulnerability has been identified in the Tenda HG10 300001138 router, specifically in the formLogin function located at /boaform/formLogin within the Boa Web Server component. The vulnerability is triggered by manipulating the Username argument, which can lead to a buffer overflow condition. The attack can be launched remotely without requiring physical access to the device. A public exploit has already been disclosed and is available for use, increasing the risk of active exploitation. This vulnerability poses a significant threat to IoT and network infrastructure devices running the affected Tenda firmware. Affected users should apply patches or mitigations as soon as they become available. The issue has been catalogued in both NVD and VulDB databases.

Affected products

  • Tenda HG10 300001138

Related CVE's

  • CVE-2026-85109

Categories

  • Mobile & IoT
  • Network Infrastructure