<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>HG10 (300001138) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/hg10-300001138/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 30 Aug 2026 15:10:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/hg10-300001138/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Buffer Overflow Vulnerability in Tenda HG10 Boa Web Server</title><link>https://feed.craftedsignal.io/briefs/2026-08-tenda-boa-buffer-overflow/</link><pubDate>Sun, 30 Aug 2026 15:10:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-tenda-boa-buffer-overflow/</guid><description>A critical buffer overflow vulnerability (CVE-2026-82542) in the Boa Web Server component of Tenda HG10 allows remote unauthenticated attackers to trigger a crash or achieve code execution via the formIPv6Routing function.</description><content:encoded><![CDATA[<p>CVE-2026-82542 describes a critical buffer overflow vulnerability found in the Tenda HG10 firmware version 300001138. The flaw resides in the 'formIPv6Routing' function within the '/boaform/admin/formIPv6Routing' URI, handled by the Boa Web Server component. An unauthenticated remote attacker can exploit this weakness by supplying a maliciously crafted 'destNet' argument in an HTTP request. Successful exploitation can lead to memory corruption, resulting in a denial-of-service condition or potentially remote code execution with the privileges of the web server. Given that public proof-of-concept exploit code is available, this vulnerability presents an immediate risk for network-connected devices.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS v3.1 base score of 10.0, indicating the highest level of severity. If exploited, an attacker could remotely compromise the integrity and availability of Tenda HG10 devices. Widespread impact on home or small office networks is expected, as attackers may gain persistent access to the network or render the device unusable.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Restrict management access to the Tenda HG10 web interface to trusted internal management subnets.</li>
<li>Monitor web server access logs for anomalous, high-length 'destNet' parameter values directed at the '/boaform/admin/formIPv6Routing' path.</li>
<li>Contact Tenda support for firmware patches addressing CVE-2026-82542; if no patch is available, disable remote management features.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>