{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-85110","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-09-03T06:54:16.121Z","datePublished":"2026-09-03T13:45:13.478Z","dateUpdated":"2026-09-03T14:58:59.386Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-09-03T13:45:13.478Z"},"title":"Tenda HG10 Boa Web Server formWlanSetup buffer overflow","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-120","lang":"en","description":"Buffer Overflow"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-119","lang":"en","description":"Memory Corruption"}]}],"affected":[{"vendor":"Tenda","product":"HG10","versions":[{"version":"300001138","status":"affected"}],"cpes":["cpe:2.3:o:tenda:hg10_firmware:*:*:*:*:*:*:*:*"],"modules":["Boa Web Server"]}],"descriptions":[{"lang":"en","value":"A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":8.7,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P","baseSeverity":"HIGH"}},{"cvssV3_1":{"version":"3.1","baseScore":8.8,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R","baseSeverity":"HIGH"}},{"cvssV3_0":{"version":"3.0","baseScore":8.8,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R","baseSeverity":"HIGH"}},{"cvssV2_0":{"version":"2.0","baseScore":9,"vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-09-03T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-09-03T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-09-03T08:59:27.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"sunnyyaya (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/vuln/398316","name":"VDB-398316 | Tenda HG10 Boa Web Server formWlanSetup buffer overflow","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/398316/cti","name":"VDB-398316 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-85110","name":"CVE-2026-85110 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/891995","name":"Submit #891995 | Tenda HG10 HG7_HG9_HG10re_300001138 Denial of Service","tags":["third-party-advisory"]},{"url":"https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/HG10/bof-formWlanSetup-ssid.md","tags":["exploit"]},{"url":"https://www.tenda.com.cn/","tags":["product"]}],"x_generator":["VulDB PVTS v202609"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-03T14:58:52.557374Z","id":"CVE-2026-85110","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-03T14:58:59.386Z"}}]}}