Skip to content
Threat Feed
critical advisory

Buffer Overflow Vulnerability in Tenda HG10 Boa Web Server

A critical buffer overflow vulnerability (CVE-2026-82542) in the Boa Web Server component of Tenda HG10 allows remote unauthenticated attackers to trigger a crash or achieve code execution via the formIPv6Routing function.

CVE search metadata

CVE search record: CVE-2026-82542. Severity: critical. CVSS: 10.0. KEV: no. Product: HG10 (300001138). Brief: Buffer Overflow Vulnerability in Tenda HG10 Boa Web Server. Brief link: https://feed.craftedsignal.io/briefs/2026-08-tenda-boa-buffer-overflow/

CVE-2026-82542 describes a critical buffer overflow vulnerability found in the Tenda HG10 firmware version 300001138. The flaw resides in the 'formIPv6Routing' function within the '/boaform/admin/formIPv6Routing' URI, handled by the Boa Web Server component. An unauthenticated remote attacker can exploit this weakness by supplying a maliciously crafted 'destNet' argument in an HTTP request. Successful exploitation can lead to memory corruption, resulting in a denial-of-service condition or potentially remote code execution with the privileges of the web server. Given that public proof-of-concept exploit code is available, this vulnerability presents an immediate risk for network-connected devices.

Impact

The vulnerability carries a CVSS v3.1 base score of 10.0, indicating the highest level of severity. If exploited, an attacker could remotely compromise the integrity and availability of Tenda HG10 devices. Widespread impact on home or small office networks is expected, as attackers may gain persistent access to the network or render the device unusable.

Recommendation

  1. Restrict management access to the Tenda HG10 web interface to trusted internal management subnets.
  2. Monitor web server access logs for anomalous, high-length 'destNet' parameter values directed at the '/boaform/admin/formIPv6Routing' path.
  3. Contact Tenda support for firmware patches addressing CVE-2026-82542; if no patch is available, disable remote management features.

Immediate actions

Block access to /boaform/admin/formIPv6Routing from untrusted networks

SOC 24h

Mitigations

Identify and isolate Tenda HG10 devices

immediate IT Operations

CVE-2026-82542

Detection coverage 1

Detects CVE-2026-82542 Exploitation - Buffer Overflow Attempt in formIPv6Routing

critical

Detects HTTP requests containing suspiciously long 'destNet' parameters directed at the Boa Web Server admin endpoint, indicative of a buffer overflow attempt.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →