CVE-2026-85110
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Scoring
- Severity
- HIGH
- CVSS base score
- 9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.48%
- CWE
- CWE-120, CWE-119
- Published
- 2026-09-03
- Last modified
- 2026-09-03
Affected products
- Tenda HG10
Weakness type
Related vulnerabilities
- CVE-2026-87931 — Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow
- CVE-2026-44756 — Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing
- CVE-2026-86166 — Tenda HG10 Boa Web Server formWanRedirect buffer overflow
- CVE-2026-86165 — Tenda HG10 formURL buffer overflow
- CVE-2026-85109 — Tenda HG10 Boa Web Server formLogin buffer overflow
- CVE-2026-85031 — TOTOLINK CP450 cstecgi.cgi buffer overflow
- CVE-2026-9625 — RSLinx Classic® - Multiple Vulnerabilities
- CVE-2026-83596 — Webkitgtk: validate the full featurelist array once in opentypeverticaldata findfeature