CVE-2026-86166
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect
CVSS
8.8
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 6, 2026 · Last modified: Sep 6, 2026 · CWE-119 · CWE-120
Not enough EPSS history yet.
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
- github.comhttps://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/HG10/bof-formWanRedirect-if.md
- vuldb.comhttps://vuldb.com/cve/CVE-2026-86166
- vuldb.comhttps://vuldb.com/submit/895595
- vuldb.comhttps://vuldb.com/vuln/399305
- vuldb.comhttps://vuldb.com/vuln/399305/cti
- www.tenda.com.cnhttps://www.tenda.com.cn/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-861659.8 CRI—
——0A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.14hCVE-2026-855225.3 MED40.7%
——12A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.c of the component Slot Migration. The manipulation of the argument job_name results in out-of-bounds read. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 9.0.5 and 9.1.1 addresses this issue. The patch is identified as f4dc3ca09eb650c2fe14060090a41c524eca803f. Upgrading the affected component is advised.2dCVE-2026-851108.8 HIG39.4%
——12A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.3dCVE-2026-851099.8 CRI47.3%
——14A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.3dCVE-2026-850319.9 CRI45.3%
——14A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible.3dCVE-2021-436146.7 MED3.0%
——1Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure.3d