Buffer Overflow Vulnerability in Tenda HG10 Router
CVE-2026-86165
Key Information:
Badges
What is CVE-2026-86165?
A critical buffer overflow vulnerability exists in the Tenda HG10 router, specifically within the formURL function of the /boaform/admin/formURL file. By manipulating the Keywd/urlFQDN argument, an attacker can trigger a buffer overflow remotely. This exploit has been disclosed publicly, raising serious concerns about the router's security. It is crucial for users of this device to remain vigilant and apply necessary security updates to mitigate potential attacks.
Affected Version(s)
HG10 300001138
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved