criticalZero-Day

Tenda HG10 formIPv6Routing Buffer Overflow (CVE-2026-82542)

First seen Sep 1, 2026 · Updated Sep 1, 2026 · CVSS 10

buffer-overflowrouteriotremote-code-executionpublic-exploittendaboa-web-server

A critical, publicly disclosed vulnerability affects the Tenda HG10 router (firmware 300001138) via its Boa Web Server admin interface. The flaw allows remote, unauthenticated attackers to trigger a buffer overflow through the destNet parameter in the formIPv6Routing function, potentially leading to full device compromise. With a CVSS score of 10.0 and public exploit code available, active exploitation is highly likely.

Technical Analysis

The vulnerability resides in the formIPv6Routing function within /boaform/admin/formIPv6Routing, part of the Boa Web Server component used in Tenda HG10 firmware. Attacker-controlled input in the destNet parameter is not properly bounds-checked, resulting in a stack or heap buffer overflow that can be exploited remotely without authentication to achieve arbitrary code execution or device denial of service. Because Boa is a lightweight embedded web server commonly reused across IoT/router firmware, this vulnerability pattern may recur in other Tenda or OEM-derived products. Compromised routers can be leveraged as botnet nodes, for traffic interception, or as pivot points into internal networks. Organizations running AI agents or LLM-based automation on networks behind vulnerable Tenda HG10 devices face risk of network-level man-in-the-middle attacks, traffic redirection, or credential/API key interception if agent traffic traverses a compromised router.

Affected Systems

Tenda HG10 routers running firmware version 300001138, specifically the Boa Web Server admin interface exposing /boaform/admin/formIPv6Routing

Indicators of Compromise

  • Endpoint pattern: /boaform/admin/formIPv6Routing
  • Parameter: destNet (oversized/malformed payload)
  • No confirmed hashes, IPs, or domains published at time of disclosure

Remediation Steps

  1. 1

    Apply Firmware Update

    Check Tenda's official support site for a patched firmware release addressing this vulnerability and apply it immediately.

  2. 2

    Restrict Admin Interface Access

    Disable remote administration and restrict access to the Boa Web Server admin panel to trusted internal IP addresses only.

  3. 3

    Network Segmentation

    Isolate IoT/router management interfaces from critical infrastructure and any systems running AI agents or automation workloads.

  4. 4

    Monitor for Exploitation Attempts

    Deploy IDS/IPS signatures to detect malformed requests to formIPv6Routing endpoints and monitor for anomalous destNet parameter values.

  5. 5

    Replace End-of-Life Devices

    If no patch is available, consider replacing affected Tenda HG10 units with actively supported hardware.

CVE / Advisory IDs

CVE-2026-82542

Industries Most Exposed

TelecommunicationsConsumer/Home NetworkingSmall Business ITCritical Infrastructure (via exposed management interfaces)Managed Service Providers

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.