Sceawere
Vulnerability Detail
CVE-2026-104610UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Tenda HG Series Buffer Overflow
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 10h ago
- Vendor
- Tenda
- Product
- HG7
- Attack Type
- Stack-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-10-02T13:17:44.450Z",
"pubdate": "2026-10-02T13:17:44.450Z",
"executiveSummary": "A critical stack-based buffer overflow vulnerability exists within the Boa Web Server component of Tenda HG7, HG9, and HG10 devices (firmware version 300001138_en_xpon).\nThe vulnerability originates from inadequate bounds checking within the boaGetVar function when processing input passed to the /boaform/formLoopBack endpoint.\nA remote, unauthenticated attacker can exploit this flaw by supplying a maliciously crafted 'Ethtype' parameter, which overflows the stack buffer.\nSuccessful exploitation allows for arbitrary code execution, potentially resulting in full system compromise, persistent unauthorized access, or device disruption.\nGiven the public availability of exploit disclosures, the risk to affected devices exposed to the network is high, necessitating immediate defensive measures.",
"technicalDetails": "The vulnerability resides in the implementation of the Boa Web Server, specifically within the handling of HTTP POST requests directed at the /boaform/formLoopBack URI.\nThe root cause is a classic stack-based buffer overflow occurring during the processing of the 'Ethtype' argument via the internal function boaGetVar.\nWhen the web server parses incoming form data, it fails to perform adequate length validation on the user-supplied input before copying the data into a fixed-size buffer allocated on the stack.\nBy providing an 'Ethtype' string that exceeds the designated memory allocation, an attacker can overwrite adjacent stack memory.\nThis overwrite provides the opportunity to modify the function's return address, effectively hijacking the execution flow of the processor.\nThe attack flow proceeds as follows: 1) The attacker transmits a specially crafted HTTP POST request to the target device; 2) The request contains an oversized 'Ethtype' parameter; 3) The boaGetVar function processes this input, copying the payload beyond the boundary of the destination stack buffer; 4) The saved instruction pointer (return address) on the stack is overwritten with an address chosen by the attacker; 5) Upon function completion, the processor jumps to the attacker-supplied memory address, facilitating arbitrary code execution.\nBecause the Boa Web Server typically runs with high privileges on these embedded devices, the resulting code execution often grants the attacker complete control over the system kernel or userland services.\nThis exploit is executable remotely over the network without requiring prior authentication, making the vulnerability particularly dangerous for devices with web management interfaces exposed to the WAN or untrusted local networks.\nThe payload behavior is limited only by the attacker's ability to craft shellcode or return-oriented programming (ROP) chains within the constraints of the stack buffer size and any potential memory protections, such as non-executable stack segments, though embedded firmware of this class often lacks modern exploit mitigations like ASLR or DEP."
}