External risk intelligence

Tenda HG Series Routers Stack Buffer Overflow Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-104610

The vulnerability affects Tenda HG series home gateway/router devices. These devices act as internet edge gateways and are designed to provide public-facing web management interfaces, making them inherently exposed to the internet in common deployment scenarios.

Memory Corruption

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A remote code execution vulnerability has been publicly disclosed, potentially impacting Tenda home gateway devices by allowing unauthorized access through a web server component. The main concern is to confirm if these specific devices are in use and exposed, as the exploit is known and may be in active use.

  • Allows remote attackers to take control.
  • Confirm relevance and exposure of affected devices.
  • Understand potential impact on network security.

Attack Path

How an attacker could exploit the issue

An attacker can remotely reach a vulnerable component on internet-facing Tenda routers by sending a specially crafted request. This request targets the Boa Web Server's `formLoopBack` function, specifically manipulating the `Ethtype` argument. Successful manipulation can lead to a stack-based buffer overflow, potentially allowing the attacker to achieve significant control over the device.

  • Unauthenticated network access required.
  • Triggered by manipulating a function argument.
  • High risk of complete device compromise.

Live Threat

Current exploitation, exposure, and threat context

A stack-based buffer overflow vulnerability in the Boa Web Server component of Tenda routers could allow an unauthenticated remote attacker to execute arbitrary code. This could occur when a specially crafted Ethtype argument is sent to the `boaGetVar` function.

  • System firmware could be compromised.
  • Remote network requests could trigger overflow.
  • Potential for complete device takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Tenda HG series home gateway/router devices are affected by this vulnerability, likely managed by infrastructure or network teams responsible for internet-facing equipment. The first practical step is to identify all instances of these devices, determine their exposure, and confirm their business criticality before planning remediation.

  • Infrastructure and network teams should own this.
  • Verify device exposure and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Tenda HG7, HG9, and HG10 equipment?

These are home gateway and router devices used to manage internet connectivity for residential or small office networks. They act as the primary bridge between a service provider's network and local devices, often hosting a web-based interface that allows users to configure network settings, wireless passwords, and firewall rules.

What does stack-based buffer overflow mean for CVE-2026-104610?

This is a memory corruption weakness categorized as CWE-121. It occurs when a program tries to store more data in a temporary memory space, known as the stack, than it can hold. By sending a malicious, oversized value in a specific request, an attacker can overwrite adjacent memory, which often allows them to hijack the device's execution flow and run unauthorized commands.

How is the vulnerability triggered?

The flaw is triggered when an attacker sends a specially crafted request to the Boa Web Server component on the router. Specifically, the attacker manipulates the 'Ethtype' argument processed by the 'boaGetVar' function within the '/boaform/formLoopBack' file. The vulnerability is not triggered by standard, legitimate configuration requests that adhere to the expected input formats and lengths.

Do I need to worry if my device is behind a firewall?

Halo Surface Signal indicates that Tenda HG series devices are often designed as internet edge gateways with management interfaces intended to be reachable. If your device is directly connected to the internet, it is at higher risk. Devices located behind additional security layers or those with management access restricted to internal-only networks face a lower probability of remote targeting.

What should I do first to manage this risk?

Begin by auditing your network inventory to identify if any Tenda HG7, HG9, or HG10 units are active in your environment. Once identified, assess their connectivity to determine if they are exposed to the public internet. Prioritize checking for firmware updates from the manufacturer and consider disabling web-based management interfaces if they are not strictly necessary for daily operations.

References