ZeroHour

CVE-2026-86166

moderate

Remote buffer overflow in Tenda HG10 router Boa web server (formWanRedirect)

CVSS 4.0
7.4 high
EPSS
<1%p40
Published
()
Modified
AI analysis

CVE-2026-86166 is a remotely exploitable buffer overflow (CWE-119/CWE-120) in the formWanRedirect function of the Boa Web Server component on Tenda HG10 routers running the 300001138 firmware. An attacker triggers it by sending a crafted request to the /boaform/formWanRedirect endpoint in which the "if" argument is manipulated to overflow a buffer; the CVSS 4.0 vector indicates the attack is network-based, requires low privileges, and needs no user interaction. Successful exploitation corrupts memory with high impact on the device's confidentiality, integrity, and availability, potentially enabling arbitrary code execution or a crash of the router's web service, although the advisory does not specify the exact primitive gained. Any Tenda HG10 unit on firmware 300001138 whose Boa web interface is reachable — particularly from the WAN — is affected. The exploit has been publicly disclosed and may be used, but the flaw is not in CISA's KEV catalog, no separate PoC is catalogued, and EPSS assigns only a 0.5% probability of exploitation within 30 days.

What to do: Check Tenda's support channels for HG10 firmware newer than 300001138 and upgrade as soon as a release is available; do not expose the router's web management interface to the internet in the meantime. Restrict WAN-side access to the Boa service (e.g., disable remote management or firewall /boaform/) and monitor for requests to /boaform/formWanRedirect carrying unusually long or malformed "if" parameter values. Since the exploit is publicly disclosed, prioritize remediation for any HG10 units reachable from the WAN.

Affected
Tenda HG10 (Boa Web Server, /boaform/formWanRedirect)300001138 (the only version cited in the advisory; no other ranges confirmed)
Estimated exposure
moderateplausibly on the order of thousands of internet-exposed devices (~1k–10k), clearly an estimate — No HG10-specific install-base data exists in the inputs; the estimate is inferred from public internet scans that have identified roughly one million exposed Boa HTTP servers, of which a single older Tenda model on this firmware is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Weakness
CWE-119, CWE-120
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.