CVE-2026-86165: Tenda HG10
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.
Affected products
- Tenda HG10: version 300001138 only
Published 2026-09-06. Last modified 2026-09-08.