ZeroHour

CVE-2026-86165

Remote Buffer Overflow in Tenda HG10 Router Web Interface

CVSS 4.0
8.9 high
EPSS
<1%p49
Published
()
Modified
AI analysis

CVE-2026-86165 is a remotely triggerable buffer overflow (CWE-119/CWE-120) in the formURL function of the admin web interface of the Tenda HG10 router/gateway, reachable through the /boaform/admin/formURL endpoint on firmware version 300001138. An attacker triggers the flaw by sending a crafted value in the Keywd/urlFQDN parameter, which overflows an internal buffer; the advisory indicates no privileges or user interaction are required (CVSS 4.0: 8.9, High). Per the CVSS scoring, successful exploitation carries high impact to the device's confidentiality, integrity, and availability — typically a crash or potential code execution — although the advisory does not confirm a specific attacker gain such as full RCE. Only deployments running the Tenda HG10 with the cited firmware whose admin web interface is reachable from an untrusted network are affected. The advisory states the exploit has been made public and could be used, but the flaw is not yet listed in CISA's KEV and EPSS currently estimates only a 0.6% probability of exploitation in the next 30 days.

What to do: Inventory networks for Tenda HG10 gateways and check whether the management web interface is exposed to the WAN or untrusted LAN segments, restricting /boaform admin endpoints to trusted management hosts. No fixed firmware version is given in the advisory, so contact Tenda or the supplying ISP for a patched build. As interim mitigation, disable WAN-side administration of affected units and monitor them for unexplained crashes or reboots.

Affected
Tenda HG10 router/gateway (boa web admin interface, /boaform/admin/formURL)300001138 (firmware version cited in the advisory; no fixed version or full affected range specified)
Estimated exposure
unknown — no public install-base, deployment, or internet-scan counts exist for the Tenda HG10 model — No public data quantifies HG10 deployments; the model is believed to be an ISP-supplied gateway, and risk is limited to units whose web admin interface serving /boaform is reachable from untrusted networks, so scale cannot be estimated…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.

Weakness
CWE-119, CWE-120
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.