Impact
A buffer overflow flaw exists in the Boa Web Server’s formLogin function on Tenda HG10 routers, triggered by a crafted Username argument. The vulnerability allows an attacker to overflow the stack and execute arbitrary code, potentially yielding full control of the device. The flaw is a classic case of CWE-119 and CWE-120, indicating improper bounds checking of user input.
Affected Systems
The vulnerability affects Tenda HG10 routers, specifically firmware version 300001138. Users running this firmware model should verify whether newer releases contain the fix.
Risk and Exploitability
The flaw carries a CVSS score of 9.3, indicating a critical severity. No EPSS data is available, and the issue is not yet listed in the CISA KEV catalog, but the exploit is publicly disclosed and can be launched remotely by sending a special Username field to the /boaform/formLogin endpoint. The attack requires no additional access privileges and could lead to full system compromise.
OpenCVE Enrichment