CVE-2026-82542
largeRemote buffer overflow in Tenda HG10 IPv6 routing handler (formIPv6Routing)
Tenda's HG10 router (firmware 300001138) contains a buffer overflow in the formIPv6Routing function of the Boa web server, triggered by a crafted destNet parameter sent to /boaform/admin/formIPv6Routing. A remote attacker who can reach the device's web administration interface can send an oversized or malformed destNet value to corrupt adjacent memory. Depending on memory layout, this can crash the management service (denial of service) and may allow arbitrary code execution, consistent with the critical 9.3 CVSS 4.0 score with high impact across confidentiality, integrity, and availability. Any Tenda HG10 deployment whose Boa web server is reachable remotely is affected, which in consumer router deployments commonly means devices with the admin interface exposed to the WAN or reachable by LAN-side attackers. A public exploit exists and could be used in attacks, though the flaw is not yet in CISA KEV and its 30-day exploitation probability (EPSS) is estimated at 0.6%.
What to do: Check Tenda's support portal for updated HG10 firmware addressing this issue and apply it when available, as no fixed version is specified in the current data. As an interim mitigation, restrict access to the device's Boa administration interface (e.g., disable WAN-side management access on /boaform or limit it to trusted management networks) and monitor devices for crashes or unexpected reboots of the management service.
| Tenda HG10 | 300001138 (firmware version as reported; no other affected ranges specified in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
- Weakness
- CWE-119, CWE-120
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.