Tenda HG10等都是中国腾达(Tenda)公司的产品。Tenda HG10是一个光猫路由器。Tenda HG9是一款WiFi路由器。Tenda HG7是一款双频Wi-Fi光网络终端设备。 Tenda多款产品存在缓冲区错误漏洞,该漏洞源于/boaform/formPPPEdit文件的formPPPEdit函数对参数encodename操作不当,可能导致栈缓冲区溢出。攻击者可远程发起攻击。以下产品及版本受到影响:Tenda HG7、HG9和HG10 300001138_en_xpon版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-11499 | 9.8 CRITICAL | Tenda HG7/HG9/HG10 formDOMAINBLK stack-based overflow |
| CVE-2026-11498 | 8.8 HIGH | Tenda HG7/HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow |
| CVE-2026-11503 | 8.8 HIGH | Tenda CX12L Wi-Fi Configuration Endpoint fast_setting_wifi_set form_fast_setting_wifi_set |
| CVE-2026-11504 | 8.8 HIGH | Tenda CX12L Wi-Fi Schedule Configuration Endpoint openSchedWifi setSchedWifi stack-based o |
| CVE-2026-11522 | 8.8 HIGH | Tenda W20E setPortMirror formSetPortMirror stack-based overflow |
| CVE-2026-11523 | 8.8 HIGH | Tenda W20E Web Management PortalAuth formPortalAuth stack-based overflow |
| CVE-2026-11524 | 8.8 HIGH | Tenda W20E Web Management modifyWifiFilterRules stack-based overflow |
| CVE-2026-11528 | 8.8 HIGH | Tenda AC18 Web Management getRebootStatus sub_45304 stack-based overflow |
| CVE-2026-11556 | 8.8 HIGH | Tenda F451 Web Management WriteFacMac formWriteFacMac os command injection |
| CVE-2026-11557 | 8.8 HIGH | Tenda F451 Web Management Natlimit fromNatlimit stack-based overflow |
| CVE-2026-11493 | 5.0 MEDIUM | Tenda AC15 Samba smb.conf weak password |
No comments yet