A remotely exploitable buffer overflow in the Tenda HG10's web administration interface is scored as allowing unauthenticated attackers to achieve full compromise of confidentiality, integrity, and availability on affected devices, and proof-of-concept exploit code is reported to be public.
What Is It
CVE-2026-86165 is a buffer overflow affecting the formURL function in the file /boaform/admin/formURL on Tenda HG10 devices running firmware 300001138. Manipulation of the Keywd/urlFQDN argument triggers the overflow. The flaw is classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-120 (classic buffer overflow), and VulDB is the CNA behind the published entry.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low complexity, no privileges, and no user interaction, with high impact to confidentiality, integrity, and availability. The CVSS 4.0 assessment scores it 8.9 (HIGH) and, critically, sets exploit maturity to PROOF_OF_CONCEPT; VulDB's entry states that the exploit has been made public and could be used. A write-up of the overflow is published on GitHub, which likely lowers the barrier to weaponization considerably. Legacy CVSS 2.0 scoring puts it at a maximum 10.0 with complete compromise across all three impact dimensions.
The available records contain no indication of in-the-wild exploitation, and none of them reference a CISA Known Exploited Vulnerabilities listing or an associated federally mandated remediation deadline. Public PoC availability against a network-edge device has nonetheless often preceded opportunistic scanning.
What's Vulnerable
- Vendor: Tenda
- Product: HG10
- Affected version: firmware 300001138
- Attack surface: the
/boaform/admin/formURLendpoint, described as reachable remotely
Patch Status
The available source material does not identify a vendor patch, fixed firmware version, or vendor advisory for this issue, and no mitigation or required action is specified in the published records. Operators of HG10 hardware should treat the administrative web interface as exposed until Tenda publishes guidance.
Sources
- VulDB, CVE-2026-86165: https://vuldb.com/cve/CVE-2026-86165
- VulDB entry 399304: https://vuldb.com/vuln/399304
- VulDB CTI data: https://vuldb.com/vuln/399304/cti
- Public technical write-up (GitHub): https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/HG10/bof-formURL-keywd.md
- VulDB submissions: https://vuldb.com/submit/895583 · https://vuldb.com/submit/895594
- Tenda vendor site: https://www.tenda.com.cn/