Impact
A buffer overflow exists in the Boa Web Server’s formIPv6Routing function, triggered by an oversized destNet argument supplied to /boaform/admin/formIPv6Routing. The overflow allows uncontrolled memory writes and could lead to arbitrary code execution. This weakness is identified as CWE-119 and CWE-120, indicating unsafe buffer manipulation and the potential for overwriting control data.
Affected Systems
The flaw affects Tenda HG10 routers running firmware version 300001138. The vulnerable component is the web server’s formIPv6Routing handler at /boaform/admin/formIPv6Routing. Any device using this firmware and exposing the web interface is potentially impacted.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. No EPSS score is available, but the published exploitation code signals a heightened risk of real-world attacks. The CVE is not listed in CISA’s KEV. The attack vector is remote, requiring only the ability to send crafted HTTP requests to the web interface which is typically reachable over the internet. Based on the description, it is inferred that a successful exploitation could compromise the router’s control plane and potentially expose network resources.
OpenCVE Enrichment