Junglewise Threat Intelligence

CVE-2026-11499: Tenda HG7/HG9/HG10 stack overflow in formDOMAINBLK

CVE-2026-11499 · Severity: critical · CVSS 9.8 · Published 2026-06-08

Vendors: Tenda.

Executive brief

A security vulnerability has been identified in Tenda HG7, HG9, and HG10 routers, which are devices used to provide fiber-optic internet connectivity. An attacker can exploit this flaw to remotely crash the router or potentially take full control of the device. This could lead to a total loss of internet service for the user or allow an unauthorized party to monitor network traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the 'formDOMAINBLK' function within the '/boaform/formDOMAINBLK' interface of Tenda HG7, HG9, and HG10 routers (firmware version 300001138_en_xpon). The root cause is the improper validation of the 'blkDomain' parameter, which allows user-controlled input to be copied into a fixed-size stack buffer. This vulnerability is reachable over the network via the web management interface without authentication. Successful exploitation can lead to a crash of the Boa web service (Denial of Service) or arbitrary code execution. As of the advisory date, no official patch has been confirmed in the provided text, though the vulnerability is publicly disclosed.

Affected products

  • Tenda HG7 xpon firmware 300001138_en_xpon
  • Tenda HG9 xpon firmware 300001138_en_xpon
  • Tenda HG10 xpon firmware 300001138_en_xpon

Timeline

  • 2026-06-08: disclosed: Vulnerability published via VulDB and NVD

References