# CVE-2026-85110

## Summary

- **CVE ID:** CVE-2026-85110
- **Severity:** HIGH
- **CVSS Score:** 9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-120, CWE-119
- **Published:** Sep 3, 2026
- **Last Modified:** Sep 3, 2026

## Description

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

## Affected Products

- Tenda — HG10 (300001138)

## References

- [CNA](https://vuldb.com/vuln/398316)
- [CNA](https://vuldb.com/vuln/398316/cti)
- [CNA](https://vuldb.com/cve/CVE-2026-85110)
- [CNA](https://vuldb.com/submit/891995)
- [CNA](https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/HG10/bof-formWlanSetup-ssid.md)
- [CNA](https://www.tenda.com.cn/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.48%
- **EPSS Percentile:** 39.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._