CVE-2026-86166CWE-119CWE-120

Tenda HG10 Boa Web Server formWanRedirect buffer overflow

High · published September 6, 2026

CVSS v3.1
8.8
EPSS
In the wild
Unconfirmed
What it is

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
EPSS
Not scored
Weaknesses
CWE-119 · Improper Restriction of Operations within the Bounds of a Memory Buffer; CWE-120 · Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Published
2026-09-06T04:00Z
Timeline
  • 06 SEP 04:00Z
    Tenda HG10 Boa Web Server formWanRedirect buffer overflow
    cvelistv5