CVE-2026-86165: Tenda HG10 formURL buffer overflow
A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
Does exploiting this issue require authentication or user interaction?
No. The CVSS vector indicates no privileges are required and no user interaction is needed.
What systems are exposed to remote exploitation?
Network-reachable Tenda HG10 devices running the identified version, 300001138, are the affected population described in the available data.
What request path and parameters should detection efforts monitor?
Monitor requests to /boaform/admin/formURL, particularly those carrying the Keywd and urlFQDN arguments. Manipulation of those arguments is identified as the trigger for the buffer overflow.
Is public exploit material available?
Yes. The available data states that an exploit has been made public and could be used.