CVE-2026-11498High· 8.8▾ TwilightA vulnerability was found in Tenda HG7, HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.8%
A vulnerability was found in Tenda HG7, HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of the argument funckey_transfer results in stack-based buffer overflow. The attack is possible to be carried out remotely.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-11553High· 8.8A vulnerability was found in Tenda HG7, HG9 and HG10 300001138_en_xpon
CVE-2026-11499Critical· 9.8A vulnerability was determined in Tenda HG7, HG9 and HG10 300001138_en_xpon
CVE-2026-90688Medium· 6.5A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC
CVE-2026-90689High· 8.8A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC
CVE-2025-14655High· 8.8A security flaw has been discovered in Tenda AC20 16.03.08.12
CVE-2025-12210High· 8.8A vulnerability was identified in Tenda O3 1.0.0.10(2478)