Impact
A buffer overflow flaw exists in the formURL function of Tenda HG10 firmware version 300001138. Manipulating the Keywd/urlFQDN argument triggers an overflow in the server’s input handling, potentially allowing an attacker to execute arbitrary code or crash the device. The vulnerability is characterized by the CWE-119 and CWE-120 weaknesses, indicating improper bounds checking and unsafe buffer operations.
Affected Systems
Tenda HG10 home gateway devices, specifically firmware iteration 300001138. The flaw is exposed through the /boaform/admin/formURL endpoint accessible on the device’s local network.
Risk and Exploitability
The CVSS score of 9.3 classifies this issue as Critical, reflecting a high likelihood of exploitation and severe impact. The EPSS score is reported as unavailable, but the public availability of an exploit suggests a non-negligible risk. The vulnerability is not listed in the CISA KEV catalog, yet the remote trigger and public exploitability elevate the immediate threat level.
OpenCVE Enrichment