A stack-based buffer overflow in the Boa web server on Tenda HG7, HG9 and HG10 devices can be triggered remotely without authentication, and a public exploit is available.
What Is It
CVE-2026-104610 is a stack-based buffer overflow in the boaGetVar function. The function is reached through the /boaform/formLoopBack endpoint of the Boa Web Server component on Tenda HG-series devices. An attacker triggers the overflow by manipulating the Ethtype argument. The weakness is classified as CWE-121 (stack-based buffer overflow) and CWE-119 (improper restriction of operations within the bounds of a memory buffer).
VulDB is the CNA that assigned the CVE. The record was published on 2026-10-02, and NVD lists its status as "Deferred."
Why It Matters
VulDB rated the flaw at the top of the severity scale:
- CVSS 3.1: 10.0 CRITICAL (
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) - CVSS 4.0: 9.3 CRITICAL, with exploit maturity marked as Proof-of-Concept
- CVSS 2.0: 10.0
The attack works over the network, has low complexity, and needs no privileges or user interaction. Under CVSS 3.1, a successful attack has a changed scope and high impact to confidentiality, integrity and availability. The CVE description says the exploit "has been disclosed publicly and may be used." A public issue in the Expl0rer-Ct/CVE GitHub repository is among the references.
CISA KEV: No KEV entry was supplied for this CVE. Based on the available data, CISA has not confirmed active exploitation in the wild. Even so, a public exploit and unauthenticated network access make this a high priority for anyone running these devices.
What's Vulnerable
The affected Tenda products are:
| Product | Affected Version | Component |
|---|---|---|
| Tenda HG7 | 300001138_en_xpon | Boa Web Server |
| Tenda HG9 | 300001138_en_xpon | Boa Web Server |
| Tenda HG10 | 300001138_en_xpon | Boa Web Server |
The affected CPEs are cpe:2.3:h:tenda:hg7, cpe:2.3:h:tenda:hg9 and cpe:2.3:h:tenda:hg10.
Patch Status
The source material does not mention a vendor patch, firmware update or advisory from Tenda. There is also no CISA required action or due date, because the CVE has no KEV entry. Owners of affected HG7, HG9 or HG10 units running firmware 300001138_en_xpon should watch Tenda's website for firmware updates. Until a fix is confirmed, they should keep the device's web management interface off untrusted networks.