CVE-2026-85110
largeBuffer Overflow in Tenda HG10 Boa Web Server via SSID Parameter
CVE-2026-85110 is a memory-corruption flaw (CWE-119/CWE-120, buffer overflow) in the formWlanSetup function of the Boa Web Server on the Tenda HG10 (firmware 300001138), triggered through the router's management web interface at /boaform/formWlanSetup. A remote attacker triggers it by submitting a manipulated ssid argument to that handler; the CVSS 4.0 vector (AV:N/PR:L/UI:N) indicates the attack requires a low-privileged (i.e., authenticated) session and no user interaction. Successful exploitation could crash the device or allow code execution, with the CVSS 4.0 scoring rating high impact on the confidentiality, integrity, and availability of the router itself. Any operator of a Tenda HG10 running firmware 300001138 whose Boa web admin interface is reachable from a hostile network is affected. The advisory states the exploit is publicly available, though no PoC is catalogued in this dataset; the issue is not in CISA KEV, and EPSS is 0.5% (40th percentile), so no confirmed in-the-wild exploitation is documented.
What to do: Restrict the router's web management interface so it is not reachable from the WAN (limit to the trusted LAN or a management VLAN) and use strong admin credentials, since exploitation requires an authenticated session; verify the firmware version against 300001138 and install updated HG10 firmware from Tenda when a fixed build is published, as the advisory does not specify a patched version. Watch for PoC/exploit activity, given the advisory notes the exploit is publicly available.
| Tenda HG10 (Boa Web Server, /boaform/formWlanSetup) | 300001138 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
- Weakness
- CWE-119, CWE-120
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.