Cyber & AI intelligence
Wasteland.
Briefs indexed2975
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-104610 2026-10-02

Tenda HG7, HG9 and HG10 xPON Routers Hit by Critical Stack Overflow in Boa Web Server (CVE-2026-104610)

"A stack-based buffer overflow in the Boa web server on Tenda HG7, HG9 and HG10 devices can be triggered remotely without authentication, and a public exploit is available."

A stack-based buffer overflow in the Boa web server on Tenda HG7, HG9 and HG10 devices can be triggered remotely without authentication, and a public exploit is available.

What Is It

CVE-2026-104610 is a stack-based buffer overflow in the boaGetVar function. The function is reached through the /boaform/formLoopBack endpoint of the Boa Web Server component on Tenda HG-series devices. An attacker triggers the overflow by manipulating the Ethtype argument. The weakness is classified as CWE-121 (stack-based buffer overflow) and CWE-119 (improper restriction of operations within the bounds of a memory buffer).

VulDB is the CNA that assigned the CVE. The record was published on 2026-10-02, and NVD lists its status as "Deferred."

Why It Matters

VulDB rated the flaw at the top of the severity scale:

The attack works over the network, has low complexity, and needs no privileges or user interaction. Under CVSS 3.1, a successful attack has a changed scope and high impact to confidentiality, integrity and availability. The CVE description says the exploit "has been disclosed publicly and may be used." A public issue in the Expl0rer-Ct/CVE GitHub repository is among the references.

CISA KEV: No KEV entry was supplied for this CVE. Based on the available data, CISA has not confirmed active exploitation in the wild. Even so, a public exploit and unauthenticated network access make this a high priority for anyone running these devices.

What's Vulnerable

The affected Tenda products are:

Product Affected Version Component
Tenda HG7 300001138_en_xpon Boa Web Server
Tenda HG9 300001138_en_xpon Boa Web Server
Tenda HG10 300001138_en_xpon Boa Web Server

The affected CPEs are cpe:2.3:h:tenda:hg7, cpe:2.3:h:tenda:hg9 and cpe:2.3:h:tenda:hg10.

Patch Status

The source material does not mention a vendor patch, firmware update or advisory from Tenda. There is also no CISA required action or due date, because the CVE has no KEV entry. Owners of affected HG7, HG9 or HG10 units running firmware 300001138_en_xpon should watch Tenda's website for firmware updates. Until a fix is confirmed, they should keep the device's web management interface off untrusted networks.

Sources