CVE-2026-85109

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Scoring

Severity
CRITICAL
CVSS base score
10
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
EPSS probability
0.62%
CWE
CWE-120, CWE-119
Published
2026-09-03
Last modified
2026-09-03

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs