Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.9
CVE-2026-85109: Tenda HG10 router login can be crashed remotely
CVE-2026-85109 · published today
Summary
The login page on Tenda HG10 routers can be tricked into overflowing its memory when a specially crafted username is sent. This could let an attacker disrupt the router or potentially take control. Update the router firmware or apply the vendor’s security patch as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| tenda | hg10 | 300001138 |
Original advisory text
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the arg...
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Severity
8.9
High
CVSS 3.1: 9.8 (MITRE)
Type
CWE-120Classic Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Monitor software like this
Free during beta