Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. | |
| Title | Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow | |
| First Time appeared |
Tenda
Tenda hg10 Tenda hg7 Tenda hg9 |
|
| Weaknesses | CWE-119 CWE-121 |
|
| CPEs | cpe:2.3:h:tenda:hg10:*:*:*:*:*:*:*:* cpe:2.3:h:tenda:hg7:*:*:*:*:*:*:*:* cpe:2.3:h:tenda:hg9:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda
Tenda hg10 Tenda hg7 Tenda hg9 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-02T13:50:12.393Z
Reserved: 2026-10-02T03:49:26.992Z
Link: CVE-2026-104610
Updated: 2026-10-02T13:50:03.515Z
Status : Deferred
Published: 2026-10-02T13:17:44.450
Modified: 2026-10-02T14:17:09.267
Link: CVE-2026-104610
No data.
OpenCVE Enrichment
Updated: 2026-10-02T14:30:23Z