CVE-2026-82542Critical· 10.0▾ MidnightA weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes b…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 31.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.6%
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86166High· 8.8A vulnerability was determined in Tenda HG10 300001138
CVE-2026-86165Critical· 9.8A vulnerability was found in Tenda HG10 300001138
CVE-2026-5567High· 8.8A flaw has been found in Tenda M3 1.0.0.10
CVE-2026-15543High· 8.8A vulnerability was found in Tenda CH22 1.0.0.1
CVE-2026-65338Medium· 4.3The issue was addressed with improved memory handling
CVE-2026-65334Medium· 4.3A memory corruption issue was addressed with improved state management