ZeroHour

CVE-2026-85109

Unauthenticated buffer overflow in Tenda HG10 Boa Web Server login

CVSS 4.0
8.9 high
EPSS
<1%p48
Published
()
Modified
AI analysis

CVE-2026-85109 is a remotely exploitable buffer overflow (CWE-119/CWE-120) in the formLogin function of the Boa Web Server component on the Tenda HG10 (firmware version 300001138). An unauthenticated attacker triggers it by sending a request to /boaform/formLogin with a manipulated Username argument. Given the high confidentiality, integrity, and availability impact ratings (CVSS 4.0 score 8.9), exploitation could crash the gateway or potentially allow full compromise of the device. Any user running the affected Tenda HG10 firmware whose web management interface is reachable, including units with WAN-side/remote administration enabled, is affected. The exploit has been publicly disclosed (CVSS exploit status: proof-of-concept), though it is not yet in CISA KEV and EPSS currently estimates only a 0.6% probability of exploitation within 30 days.

What to do: Identify any Tenda HG10 devices in your environment and check whether they run firmware 300001138; apply Tenda's patched firmware when it is released, as no fixed version is specified in the advisory. In the meantime, disable WAN-side/remote management and restrict access to the device's Boa web interface (the login endpoint /boaform/formLogin) to trusted networks only. Monitor for unexplained device reboots or crashes, which may indicate exploitation attempts.

Affected
Tenda HG10300001138
Estimated exposure
unknown — no public install-base counts or internet-exposure scan data exist for this specific model — No plugin counts, market-share figures, or public scan data are available for the Tenda HG10, so any deployment figure would be speculation; consumer gateways of this class are typically administered from the LAN, which would limit the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Weakness
CWE-119, CWE-120
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.