CVE-2026-85109
Unauthenticated buffer overflow in Tenda HG10 Boa Web Server login
CVE-2026-85109 is a remotely exploitable buffer overflow (CWE-119/CWE-120) in the formLogin function of the Boa Web Server component on the Tenda HG10 (firmware version 300001138). An unauthenticated attacker triggers it by sending a request to /boaform/formLogin with a manipulated Username argument. Given the high confidentiality, integrity, and availability impact ratings (CVSS 4.0 score 8.9), exploitation could crash the gateway or potentially allow full compromise of the device. Any user running the affected Tenda HG10 firmware whose web management interface is reachable, including units with WAN-side/remote administration enabled, is affected. The exploit has been publicly disclosed (CVSS exploit status: proof-of-concept), though it is not yet in CISA KEV and EPSS currently estimates only a 0.6% probability of exploitation within 30 days.
What to do: Identify any Tenda HG10 devices in your environment and check whether they run firmware 300001138; apply Tenda's patched firmware when it is released, as no fixed version is specified in the advisory. In the meantime, disable WAN-side/remote management and restrict access to the device's Boa web interface (the login endpoint /boaform/formLogin) to trusted networks only. Monitor for unexplained device reboots or crashes, which may indicate exploitation attempts.
| Tenda HG10 | 300001138 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
- Weakness
- CWE-119, CWE-120
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.