Cyber & AI intelligence
Wasteland.
Briefs indexed2326
Issues25
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-82542 2026-08-30

CVE-2026-82542: Critical Buffer Overflow in Tenda HG10 Boa Web Server

"A reported buffer overflow in the Tenda HG10 router's IPv6 routing handler is described as allowing unauthenticated remote attackers to compromise the device, and carries a maximum CVSS 3.1 base score of 10.0 in the…"

A reported buffer overflow in the Tenda HG10 router's IPv6 routing handler is described as allowing unauthenticated remote attackers to compromise the device, and carries a maximum CVSS 3.1 base score of 10.0 in the submitted data. The NVD record is still in Received status, so none of these details have been validated by NVD analysts.

What Is It

CVE-2026-82542 is described as a buffer overflow (CWE-119, CWE-120) in the formIPv6Routing function of /boaform/admin/formIPv6Routing in the Boa Web Server component of Tenda HG10 firmware version 300001138. Manipulation of the destNet argument is said to trigger the overflow. The attack is reported to be exploitable remotely, and per the NVD record, the exploit has been made available to the public. These claims originate from the submitted advisory data and the linked public write-up; they have not been independently confirmed here or by NVD.

Why It Matters

The record lists a CVSS 3.1 base score of 10.0 (CRITICAL). Note that the accompanying vector string, CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, is internally inconsistent: it is prefixed as CVSS 4.0 but uses CVSS 3.1 metrics (notably S:C, which does not exist in CVSS 4.0). Read as a CVSS 3.1 vector, it describes a network-reachable flaw with low attack complexity, no privileges, no user interaction, and a changed scope with complete confidentiality, integrity, and availability impact. The separate CVSS 4.0 assessment scores 9.3 (CRITICAL) and rates exploit maturity as Proof-of-Concept, reflecting the public exploit code referenced in the advisory. Both scores are supplier-provided rather than NVD-assigned, and should be treated as provisional until the record is analyzed.

If the report is accurate, a pre-authentication overflow in an embedded web server exposed on a consumer/SOHO gateway is the classic path to device takeover and persistent foothold on the network edge. The changed-scope rating, as submitted, would mean impact is not confined to the web server process.

What's Vulnerable

Per the unvalidated NVD record:

Because the record has not been analyzed, the affected-version list may be incomplete; other firmware builds sharing the same Boa handler could be affected.

Patch Status

No CISA KEV entry exists for this CVE, there is no confirmation of active in-the-wild exploitation in the supplied data, and no KEV-mandated remediation deadline applies. The NVD record is in Received status (published 2026-08-30) and contains no vendor patch, fixed version, or mitigation guidance. Pending vendor confirmation, operators should treat the affected endpoint as potentially exposed and restrict remote access to the device's web management interface.

Sources