CVE-2026-82542

10.0

Tenda · HG10

A buffer overflow vulnerability in the Tenda HG10 Boa web server allows unauthenticated remote attackers to trigger a denial of service via the formIPv6Routing interface.

Executive summary

A critical remote buffer overflow vulnerability in Tenda HG10 routers poses a severe risk of system compromise and denial of service.

Vulnerability

This memory corruption flaw exists in the formIPv6Routing function of the Boa web server, where insufficient validation of the destNet parameter allows an unauthenticated remote attacker to overflow a fixed-size buffer.

Business impact

Successful exploitation of this buffer overflow can lead to a complete denial of service, rendering the device unresponsive and disrupting network connectivity for all dependent users. Given the CVSS score of 10.0, the potential for arbitrary code execution poses a critical risk to data integrity and network security, as attackers could gain unauthorized control over the routing infrastructure.

Remediation

Immediate Action: Contact Tenda support or monitor the official vendor website for a firmware update that addresses this buffer overflow in the Boa web server.

Proactive Monitoring: Inspect network traffic for unusually large POST requests directed at the /boaform/admin/formIPv6Routing endpoint and monitor device logs for unexpected reboots or system crashes.

Compensating Controls: Restrict access to the device administration interface to trusted internal IP addresses using firewall rules, and employ a Web Application Firewall (WAF) to filter malformed HTTP requests containing excessively long parameters.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the research write-up by SunnyYANGyaya.

Analyst recommendation

Due to the critical nature of this vulnerability and the availability of public exploit details, immediate action is required to secure affected Tenda HG10 devices. Organizations should prioritize isolating these units from the public internet until a firmware patch is applied to prevent potential remote exploitation.

More Tenda CVEs

Sources

Originally found and disclosed by sunnyyaya (VulDB User), per the CVE Program record.