在 Tenda HG10 固件版本 300001138 中发现一个漏洞。该问题影响 Boa Web Server 组件中文件 的 函数。对参数 进行恶意操纵可能引发缓冲区溢出漏洞。攻击可远程发起,该漏洞的利用方法已公开披露,可能被攻击者利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86152 | 10.0 CRITICAL | Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection |
| CVE-2026-86167 | 9.9 CRITICAL | Tenda HG10 Boa formgponConf os command injection |
| CVE-2026-86165 | 9.8 CRITICAL | Tenda HG10 formURL buffer overflow |
| CVE-2026-86153 | 9.1 CRITICAL | Tenda CP3 Redirect.cpp SetRedirectEnable privileges management |
No comments yet