Description
A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2026-06-08: | Advisory disclosed |
| 2026-06-08: | VulDB entry created |
| 2026-06-08: | VulDB entry last update |
Credits
zhihua xie (VulDB User)
References
vuldb.com/vuln/369163 (VDB-369163 | Tenda HG7HG9/HG10 formPPPEdit stack-based overflow)
vuldb.com/vuln/369163/cti (VDB-369163 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/cve/CVE-2026-11553 (CVE-2026-11553 | CVE Analysis and Report)
vuldb.com/submit/836778 (Submit #836778 | Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon stack-based buffer overflow)
github.com/xiezhihua-1127/Tenda-Stack-Overflow.git
github.com/...-1127/Tenda-Stack-Overflow/blob/main/report.md
www.tenda.com.cn/