Description
A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 02 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. | |
| Title | Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow | |
| First Time appeared |
Tenda
Tenda hg10 Tenda hg7 Tenda hg9 |
|
| Weaknesses | CWE-119 CWE-121 |
|
| CPEs | cpe:2.3:h:tenda:hg10:*:*:*:*:*:*:*:* cpe:2.3:h:tenda:hg7:*:*:*:*:*:*:*:* cpe:2.3:h:tenda:hg9:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda
Tenda hg10 Tenda hg7 Tenda hg9 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-02T12:00:18.544Z
Reserved: 2026-10-02T03:49:26.992Z
Link: CVE-2026-104610
No data.
No data.
No data.
OpenCVE Enrichment
No data.