Tenda Hg10 Firmware
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Tenda Hg10 Firmware.
By the Year
In 2026 there have been 10 vulnerabilities in Tenda Hg10 Firmware with an average score of 8.4 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 10 | 8.35 |
It may take a day or so for new Hg10 Firmware vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Tenda Hg10 Firmware Security Vulnerabilities
OS Command Injection in Tenda HG10's Boa formgponConf via fmgpon_loid
CVE-2026-86167
9.4 - Critical
- September 06, 2026
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Shell injection
Tenda HG10 BoaWS Buffer Overflow via formWanRedirect
CVE-2026-86166
8.7 - High
- September 06, 2026
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Classic Buffer Overflow
Tenda HG10 Buffer Overflow in formURL Function (Remote Exploit)
CVE-2026-86165
9.3 - Critical
- September 06, 2026
A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.
Classic Buffer Overflow
Tenda HG10 Boa Web Server ssid Buffer Overflow (CVE-2026-85110)
CVE-2026-85110
8.7 - High
- September 03, 2026
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Classic Buffer Overflow
Boa Web Server Buffer Overflow in Tenda HG10 Login
CVE-2026-85109
9.3 - Critical
- September 03, 2026
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Classic Buffer Overflow
Tenda HG10 Boa Web Server formIPv6Routing Buffer Overflow (CVE-2026-82542)
CVE-2026-82542
10 - Critical
- August 30, 2026
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Classic Buffer Overflow
Tenda HG10 Boa Service buffer overflow via nextHop
CVE-2026-6988
8.8 - High
- April 25, 2026
A flaw has been found in Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon. This issue affects the function formRoute of the file /boaform/formRouting of the component Boa Service. This manipulation of the argument nextHop causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Classic Buffer Overflow
Tenda HG10 Router /boaform/formSysCmd Command Injection
CVE-2026-1690
4.7 - Medium
- January 30, 2026
A flaw has been found in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. This affects the function system of the file /boaform/formSysCmd. This manipulation of the argument sysCmd causes command injection. The attack may be initiated remotely. The exploit has been published and may be used.
Command Injection
Tenda HG10 Cmd Injection via Host in Login Interface
CVE-2026-1689
7.3 - High
- January 30, 2026
A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function checkUserFromLanOrWan of the file /boaform/admin/formLogin of the component Login Interface. The manipulation of the argument Host results in command injection. The attack can be launched remotely. The exploit is now public and may be used.
Command Injection
CVE-2026-1687: Command Injection in Tenda HG10 Boa Webserver
CVE-2026-1687
7.3 - High
- January 30, 2026
A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. Impacted is an unknown function of the file /boaform/formSamba of the component Boa Webserver. Executing a manipulation of the argument serverString can lead to command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
Command Injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Tenda Hg10 Firmware or by Tenda? Click the Watch button to subscribe.