← Terug naar overzicht

A buffer overflow vulnerability has been identified in the Tenda HG10 router, firmware version 300001138. The flaw exists in the formURL function located at /boaform/admin/formURL. Attackers can exploit this by manipulating the Keywd or urlFQDN arguments to trigger a buffer overflow condition. The vulnerability can be exploited remotely without requiring physical access to the device. A public exploit has been released, increasing the risk of active exploitation. The affected product is a consumer/SOHO networking device manufactured by Tenda. This type of vulnerability in IoT/networking devices is commonly leveraged for unauthorized access or device compromise. Users and administrators are advised to apply patches or mitigations as soon as they become available. The public disclosure and exploit availability elevate the urgency of remediation.

Affected products

  • Tenda HG10 300001138

Related CVE's

  • CVE-2026-86165

Categories

  • Mobile & IoT
  • Network Infrastructure