CVE-2026-85109: Tenda HG10 Boa Web Server formLogin buffer overflow
Published Sep 3, 2026
·Updated
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
2 affected components
Tenda HG10=300001138
Tenda Boa Web Server
Event History
Sep 3, 2026
CVE Published
via MITRE·01:30 PM
Data Sourced
via MITRE·01:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack can be launched remotely and requires manipulation of the Username argument sent to the /boaform/formLogin endpoint. The supplied severity vector indicates no privileges or user interaction are required.
2
Which systems are identified as affected?
The issue is identified in Tenda HG10 version 300001138, in the Boa Web Server component's formLogin function.
3
Is exploit code available?
Yes. The exploit has been publicly disclosed and may be used.