Description
A vulnerability was found in Tenda HG7, HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of the argument funckey_transfer results in stack-based buffer overflow. The attack is possible to be carried out remotely.
Published: 2026-06-08
Score: 8.7 High
EPSS: 3.8% Low
KEV: No
Impact: Potential arbitrary code execution via stack-based buffer overflow
Action: Patch
AI Analysis

Impact

A vulnerability in firmware 300001138_en_xpon of Tenda HG7, HG9, and HG10 routers exposes a stack‑based buffer overflow in the Web Management Interface. The flaw affects the asp_voip_OtherSet function exposed at /boaform/voip_other_set. Manipulating the funckey_transfer argument overflows the stack, potentially enabling arbitrary code execution with the web service’s privileges. The weakness conforms to CWE‑119 and CWE‑121.

Affected Systems

The affected devices are Tenda HG7, HG9, and HG10 routers running firmware version 300001138_en_xpon, distributed by Tenda. The vulnerability resides in the web interface component and is triggered by requests to the voip_other_set endpoint.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and the EPSS score of 4% suggests a moderate probability of exploitation in the wild. Based on the description, it is inferred that the exploit can be carried out remotely via the router’s web management interface and that authentication is not explicitly required, so the endpoint is likely publicly reachable from any host that can connect to the service. The vulnerability is not currently listed in CISA’s KEV catalog, but its remote reach and high severity demand prompt remediation.

Generated by OpenCVE AI on October 2, 2026 at 05:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by Tenda that addresses the buffer overflow in the voip_other_set functionality.
  • If a patch is not yet available, block external access to the /boaform/voip_other_set URL or to the entire web management interface using firewall rules or access control lists to narrow the attack surface.
  • Restrict the web management interface to trusted IP addresses or a secured VPN, and disable remote management unless absolutely required.
  • Enable logging for HTTP requests and monitor the logs or deploy an intrusion detection system to alert on abnormal or repeated access attempts to the voip_other_set endpoint.

Generated by OpenCVE AI on October 2, 2026 at 05:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 04:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of the argument funckey_transfer results in stack-based buffer overflow. The attack is possible to be carried out remotely. A vulnerability was found in Tenda HG7, HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of the argument funckey_transfer results in stack-based buffer overflow. The attack is possible to be carried out remotely.
Title Tenda HG7HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow Tenda HG7/HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow
First Time appeared Tenda hg7
Tenda hg9
CPEs cpe:2.3:h:tenda:hg7hg9:*:*:*:*:*:*:*:* cpe:2.3:h:tenda:hg7:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:hg9:*:*:*:*:*:*:*:*
Vendors & Products Tenda hg7
Tenda hg9

Mon, 08 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 08 Jun 2026 08:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of the argument funckey_transfer results in stack-based buffer overflow. The attack is possible to be carried out remotely.
Title Tenda HG7HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow
First Time appeared Tenda
Tenda hg10
Tenda hg7hg9
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:h:tenda:hg10:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:hg7hg9:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda hg10
Tenda hg7hg9
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-02T03:48:52.157Z

Reserved: 2026-06-07T13:22:12.336Z

Link: CVE-2026-11498

cve-icon Vulnrichment

Updated: 2026-06-08T12:47:44.844Z

cve-icon NVD

Status : Deferred

Published: 2026-06-08T09:16:29.753

Modified: 2026-10-02T04:18:05.103

Link: CVE-2026-11498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T06:00:11Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow