CVE-2026-86165CWE-119CWE-120

Tenda HG10 formURL buffer overflow

Critical · published September 6, 2026

CVSS v3.1
9.8
EPSS
In the wild
Unconfirmed
What it is

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
CVSS v4.0
9.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
EPSS
Not scored
Weaknesses
CWE-119 · Improper Restriction of Operations within the Bounds of a Memory Buffer; CWE-120 · Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Published
2026-09-06T03:30Z
Timeline
  • 06 SEP 03:30Z
    Tenda HG10 formURL buffer overflow
    cvelistv5