CRITICAL 9.3 NVD
CVE-2026-82542
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
References
- https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/HG10/bof-formIP
- https://vuldb.com/cve/CVE-2026-82542
- https://vuldb.com/submit/888876
- https://vuldb.com/vuln/397058
- https://vuldb.com/vuln/397058/cti
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-30 via NVD.
Risk Timeline
CVE Disclosed2026-08-30 · -1 days ago
Remediation Resources
Official Advisory
vuldb.com/cve/CVE-2026-82542Official Advisory
vuldb.com/vuln/397058Analysis & PoC
vuldb.com/submit/888876
vulnfeed aggregates 11450 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.