HIGH 7.4 NVD
CVE-2026-85110
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Serve
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
References
- https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/HG10/bof-formWl
- https://vuldb.com/cve/CVE-2026-85110
- https://vuldb.com/submit/891995
- https://vuldb.com/vuln/398316
- https://vuldb.com/vuln/398316/cti
This high severity vulnerability with a CVSS score of 7.4 was published on 2026-09-03 via NVD.
vulnfeed aggregates 7805 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.