CWE-120Base5 in KEV

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Incomplete in the CWE catalog · 2,022 CVEs mapped

2,022
CVEs mapped
5
In KEV
7.8
Median CVSS
What it is

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Recent examples
8.8cvss
CVE-2026-86166

Tenda HG10 Boa Web Server formWanRedirect buffer overflow

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

HIGHno explanation yet
epss
9.8cvss
CVE-2026-86165

Tenda HG10 formURL buffer overflow

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.

CRITICALno explanation yet
epss
8.8cvss
CVE-2026-85110

CVE-2026-85110 - HIGH Severity Vulnerability

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-120
Abstraction
Base
Structure
Simple
Status
Incomplete
References (20)