Tenda HG10 formIPv6Routing Buffer Overflow (CVE-2026-82542)
First seen Sep 1, 2026 · Updated Sep 1, 2026 · CVSS 10
A critical, publicly disclosed vulnerability affects the Tenda HG10 router (firmware 300001138) via its Boa Web Server admin interface. The flaw allows remote, unauthenticated attackers to trigger a buffer overflow through the destNet parameter in the formIPv6Routing function, potentially leading to full device compromise. With a CVSS score of 10.0 and public exploit code available, active exploitation is highly likely.
Technical Analysis
The vulnerability resides in the formIPv6Routing function within /boaform/admin/formIPv6Routing, part of the Boa Web Server component used in Tenda HG10 firmware. Attacker-controlled input in the destNet parameter is not properly bounds-checked, resulting in a stack or heap buffer overflow that can be exploited remotely without authentication to achieve arbitrary code execution or device denial of service. Because Boa is a lightweight embedded web server commonly reused across IoT/router firmware, this vulnerability pattern may recur in other Tenda or OEM-derived products. Compromised routers can be leveraged as botnet nodes, for traffic interception, or as pivot points into internal networks. Organizations running AI agents or LLM-based automation on networks behind vulnerable Tenda HG10 devices face risk of network-level man-in-the-middle attacks, traffic redirection, or credential/API key interception if agent traffic traverses a compromised router.
Affected Systems
Tenda HG10 routers running firmware version 300001138, specifically the Boa Web Server admin interface exposing /boaform/admin/formIPv6Routing
Indicators of Compromise
- Endpoint pattern: /boaform/admin/formIPv6Routing
- Parameter: destNet (oversized/malformed payload)
- No confirmed hashes, IPs, or domains published at time of disclosure
Remediation Steps
- 1
Apply Firmware Update
Check Tenda's official support site for a patched firmware release addressing this vulnerability and apply it immediately.
- 2
Restrict Admin Interface Access
Disable remote administration and restrict access to the Boa Web Server admin panel to trusted internal IP addresses only.
- 3
Network Segmentation
Isolate IoT/router management interfaces from critical infrastructure and any systems running AI agents or automation workloads.
- 4
Monitor for Exploitation Attempts
Deploy IDS/IPS signatures to detect malformed requests to formIPv6Routing endpoints and monitor for anomalous destNet parameter values.
- 5
Replace End-of-Life Devices
If no patch is available, consider replacing affected Tenda HG10 units with actively supported hardware.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.