Executive brief
A vulnerability exists in several Tenda router models (HG7, HG9, and HG10) used for fiber-optic internet connections. An attacker can exploit this flaw to crash the device's management interface or potentially take full control of the router. This could lead to a complete loss of internet connectivity for the user or unauthorized access to network traffic.
Technical details
A stack-based buffer overflow (CWE-121) exists in the Tenda HG7, HG9, and HG10 router firmware (version 300001138_en_xpon). The vulnerability is located in the 'formPPPEdit' function within the '/boaform/formPPPEdit' component. It is triggered by providing an overly long string to the 'encodename' parameter. While some reports suggest low privileges are required, others indicate it may be unauthenticated. Successful exploitation allows an attacker to crash the Boa web service (Denial of Service) or achieve arbitrary code execution with root privileges. A public exploit has been disclosed.
Affected products
- Tenda HG7 300001138_en_xpon
- Tenda HG9 300001138_en_xpon
- Tenda HG10 AC1200 Dual-Band Wi-Fi xPON ONT 300001138_en_xpon
Timeline
- 2026-06-08: disclosed: Vulnerability disclosed and CVE assigned
- 2026-06-08: advisory: NVD and VulDB published advisory details