Junglewise Threat Intelligence

CVE-2026-11498: Tenda HG7/HG9/HG10 stack overflow in Web Management Interface

CVE-2026-11498 · Severity: high · CVSS 8.8 · Published 2026-06-08

Technologies: Tenda HG10. Vendors: Tenda.

Executive brief

A vulnerability exists in the web management interface of Tenda HG7, HG9, and HG10 routers, which are devices used to provide fiber-optic internet connectivity. An attacker with access to the management console can exploit this flaw to crash the device or potentially take full control of it. This could lead to a complete loss of internet service or unauthorized access to the local network.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda HG7, HG9, and HG10 router firmware (version 300001138_en_xpon). The flaw is located within the 'asp_voip_OtherSet' function in the '/boaform/voip_other_set' component of the Web Management Interface. By sending a specially crafted request with a manipulated 'funckey_transfer' argument, a remote attacker with low-level authentication can overflow a buffer on the stack. This can result in a denial of service (system crash) or the execution of arbitrary code with the privileges of the web server.

Affected products

  • Tenda HG7 300001138_en_xpon
  • Tenda HG9 300001138_en_xpon
  • Tenda HG10 300001138_en_xpon

Timeline

  • 2026-06-08: disclosed: Vulnerability published via VulDB and NVD

References

Related threats