CVE-2026-11498: Tenda HG7HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow
A vulnerability was found in Tenda HG7HG9 and HG10 300001138enxpon. Affected by this issue is the function aspvoipOtherSet of the file /boaform/voipotherset of the component Web Management Interface. Performing a manipulation of the argument funckeytransfer results in stack-based buffer overflow. The attack is possible to be carried out remotely.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable remote (WAN) web management access, or restrict web management to LAN and specific trusted IP addresses to prevent remote exploitation of /boaform/voip_other_set (asp_voip_OtherSet).
Web Management Interface remote_management = disabled or restricted to LAN/trusted IPs - Configuration
Disable web-based VOIP configuration or disable the VOIP feature on the device if it is not required to remove exposure of the asp_voip_OtherSet handler and the funckey_transfer parameter.
VOIP web configuration (/boaform/voip_other_set) web_voip_configuration = disabled if not required
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11498?
CVE-2026-11498 has a high severity rating of 8.8.
How do I fix CVE-2026-11498?
To fix CVE-2026-11498, update the Tenda HG7HG9 or HG10 firmware to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-11498?
CVE-2026-11498 is classified as a stack-based buffer overflow vulnerability.
Which devices are affected by CVE-2026-11498?
The affected devices include the Tenda HG7HG9 and HG10 models.
What component of Tenda devices does CVE-2026-11498 impact?
CVE-2026-11498 impacts the Web Management Interface function asp_voip_OtherSet.