← back
CVE-2026-82542criticalCWE-119CWE-120

Tenda HG10 Boa Web Server formIPv6Routing buffer overflow

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 10epss 0.6%
exploitation probability
0.6%top 51% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
Affected products
Tenda · HG10
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.