{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hg10-300001138/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tenda:hg10:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-82542"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HG10 (300001138)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Tenda"],"content_html":"\u003cp\u003eCVE-2026-82542 describes a critical buffer overflow vulnerability found in the Tenda HG10 firmware version 300001138. The flaw resides in the 'formIPv6Routing' function within the '/boaform/admin/formIPv6Routing' URI, handled by the Boa Web Server component. An unauthenticated remote attacker can exploit this weakness by supplying a maliciously crafted 'destNet' argument in an HTTP request. Successful exploitation can lead to memory corruption, resulting in a denial-of-service condition or potentially remote code execution with the privileges of the web server. Given that public proof-of-concept exploit code is available, this vulnerability presents an immediate risk for network-connected devices.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 10.0, indicating the highest level of severity. If exploited, an attacker could remotely compromise the integrity and availability of Tenda HG10 devices. Widespread impact on home or small office networks is expected, as attackers may gain persistent access to the network or render the device unusable.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eRestrict management access to the Tenda HG10 web interface to trusted internal management subnets.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous, high-length 'destNet' parameter values directed at the '/boaform/admin/formIPv6Routing' path.\u003c/li\u003e\n\u003cli\u003eContact Tenda support for firmware patches addressing CVE-2026-82542; if no patch is available, disable remote management features.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-30T15:10:52Z","date_published":"2026-08-30T15:10:52Z","id":"https://feed.craftedsignal.io/briefs/2026-08-tenda-boa-buffer-overflow/","summary":"A critical buffer overflow vulnerability (CVE-2026-82542) in the Boa Web Server component of Tenda HG10 allows remote unauthenticated attackers to trigger a crash or achieve code execution via the formIPv6Routing function.","title":"Buffer Overflow Vulnerability in Tenda HG10 Boa Web Server","url":"https://feed.craftedsignal.io/briefs/2026-08-tenda-boa-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - HG10 (300001138)","version":"https://jsonfeed.org/version/1.1"}