CVE-2026-86166: Tenda HG10 Boa Web Server formWanRedirect buffer overflow
Published Sep 6, 2026
·Updated
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
2 affected components
Tenda HG10=300001138
Tenda Boa Web Server
Event History
Sep 6, 2026
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attack can be launched remotely and requires low privileges. No user interaction is required.
2
Which component and input are involved?
The affected code is the formWanRedirect function exposed through /boaform/formWanRedirect in the Boa Web Server component. The buffer overflow is triggered by manipulating the if argument.
3
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used by attackers.