Sceawere

Vulnerability Detail

CVE-2026-86166UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Tenda HG10 Buffer Overflow

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
Tenda
Product
HG10
Attack Type
Buffer Overflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-06T04:18:32.783Z",
  "pubdate": "2026-09-06T04:18:32.783Z",
  "executiveSummary": "A buffer overflow vulnerability exists in the Tenda HG10 300001138 within the Boa Web Server component.\nThe vulnerability resides in the formWanRedirect function, specifically triggered via improper input validation of the 'if' argument.\nThis flaw allows a remote, unauthenticated attacker to inject malicious data that exceeds allocated memory boundaries, potentially leading to arbitrary code execution.\nThe impact includes system compromise, unauthorized access, or denial of service, depending on the payload injected.\nAs this vulnerability is publicly disclosed, the risk of exploitation is significantly increased for internet-facing devices.\nNo complex exploitation requirements are noted, as the vulnerability is accessible via remote network requests.",
  "technicalDetails": "The vulnerability is a classic stack-based buffer overflow occurring within the Boa Web Server component of the Tenda HG10 300001138 firmware.\nThe root cause is identified in the formWanRedirect function, located within the /boaform/formWanRedirect file, which processes HTTP POST requests.\nDuring the parsing of these requests, the function fails to adequately sanitize or validate the length of the 'if' argument before performing memory copy operations, such as 'strcpy' or 'sprintf', into a fixed-size stack buffer.\nAn attacker can exploit this by crafting a malicious HTTP request where the 'if' parameter contains a payload longer than the target buffer's capacity.\nThe attack flow proceeds as follows: First, the attacker identifies the target device's web management interface. Second, the attacker sends a specially crafted POST request directed at the /boaform/formWanRedirect endpoint. Third, the payload is submitted via the 'if' argument, causing the buffer overflow.\nBy overwriting the return address on the stack, the attacker can hijack the instruction pointer to redirect execution flow to attacker-controlled memory, such as a shellcode payload provided within the request.\nBecause the Boa Web Server typically runs with elevated privileges, successful exploitation grants the attacker extensive control over the affected hardware, potentially leading to persistent device compromise or unauthorized network modification.\nThe vulnerability is exposed remotely, meaning an attacker does not require physical access or prior authentication to trigger the overflow, provided the administrative interface is accessible via the network.\nThe impact includes the ability to bypass security controls, execute arbitrary commands with administrative privileges, or cause the web server process to crash, resulting in a denial-of-service condition."
}
CVE-2026-86166: Tenda HG10 Buffer Overflow (HIGH Severity, CVSS: 8.8) - Sceawere