CVE-2026-104610 Overview
CVE-2026-104610 is a stack-based buffer overflow [CWE-119] in Tenda HG7, HG9, and HG10 XPON optical network terminals running firmware 300001138_en_xpon. The flaw resides in the boaGetVar function within /boaform/formLoopBack, served by the embedded Boa Web Server. Attackers manipulate the Ethtype argument to corrupt stack memory and influence program flow. The attack requires no authentication and can be executed over the network. A public exploit disclosure has been released, raising the probability of opportunistic exploitation against exposed devices.
Critical Impact
Unauthenticated remote attackers can trigger a stack-based buffer overflow in the Boa Web Server, enabling potential remote code execution on affected Tenda HG7, HG9, and HG10 XPON devices.
Affected Products
- Tenda HG7 (firmware 300001138_en_xpon)
- Tenda HG9 (firmware 300001138_en_xpon)
- Tenda HG10 (firmware 300001138_en_xpon)
Discovery Timeline
- 2026-10-02 - CVE-2026-104610 published to the National Vulnerability Database (NVD)
- 2026-10-02 - Last updated in NVD database
Technical Details for CVE-2026-104610
Vulnerability Analysis
The vulnerability affects the boaGetVar routine in /boaform/formLoopBack, a handler exposed by the Boa Web Server embedded in Tenda XPON gateways. The handler reads the Ethtype parameter from an HTTP request and copies it into a fixed-size stack buffer without enforcing length validation. Supplying an oversized value overwrites adjacent stack memory, including saved registers and the return address. The flaw is classified under [CWE-119] (Improper Restriction of Operations within the Bounds of a Memory Buffer). Successful exploitation can lead to arbitrary code execution with the privileges of the web server process, which on consumer-grade routers typically runs as root.
Root Cause
The root cause is missing bounds enforcement on the Ethtype input before it is written into a stack-allocated buffer. The Boa Web Server relies on unsafe string handling in boaGetVar, allowing user-supplied HTTP parameters to exceed the destination buffer size. No input length checks or canonical sanitization occur before the copy operation.
Attack Vector
An attacker crafts an HTTP request to /boaform/formLoopBack with an oversized Ethtype parameter. The request requires no credentials and can be delivered across the network, including from the WAN interface if the management service is reachable. A public proof-of-concept has been referenced in the GitHub CVE Issue Tracker and corroborated by the VulDB Vulnerability Details entry. The EPSS forecast for this CVE is 0.644% (49.266 percentile) as of 2026-10-08.
Technical details are available in the VulDB CVE Entry and the VulDB CTI Insights report.
Detection Methods for CVE-2026-104610
Indicators of Compromise
- Unusual HTTP POST or GET requests to /boaform/formLoopBack containing abnormally long Ethtype parameter values.
- Unexpected restarts or crashes of the Boa Web Server process on Tenda HG7, HG9, or HG10 devices.
- Outbound connections from the router to unknown command-and-control hosts following suspicious management-interface activity.
Detection Strategies
- Deploy network IDS or WAF signatures that flag HTTP requests to /boaform/formLoopBack with Ethtype parameter lengths beyond expected input ranges.
- Correlate router syslog events indicating Boa process termination with inbound HTTP traffic patterns to identify exploitation attempts.
- Monitor perimeter telemetry for scanning activity targeting the /boaform/ URI path common to Boa-based device management interfaces.
Monitoring Recommendations
- Centralize router and gateway logs into a SIEM for continuous review of administrative interface access.
- Alert on authentication-less requests to formLoopBack and other boaform endpoints from untrusted networks.
- Baseline normal management traffic volumes and investigate deviations that could indicate automated exploitation.
How to Mitigate CVE-2026-104610
Immediate Actions Required
- Restrict access to the device management interface to trusted LAN segments and block WAN-side exposure of HTTP services.
- Disable remote administration on Tenda HG7, HG9, and HG10 devices until a vendor patch is available.
- Inventory affected devices running firmware 300001138_en_xpon and prioritize them for mitigation and replacement planning.
Patch Information
At time of publication, no vendor patch has been referenced in the public advisory. Consult the Tenda Official Website for firmware updates and subscribe to vendor security notifications. Review the VulDB Submission Confirmation for any coordinated vendor response.
Workarounds
- Place affected XPON devices behind a network firewall that filters inbound HTTP traffic to the device management interface.
- Enforce access control lists restricting /boaform/ URI access to specific administrative source IPs.
- Where feasible, replace end-of-life or unpatched Tenda XPON hardware with vendor-supported models that receive active security updates.
# Example firewall rule to block external access to the Boa management interface
iptables -I INPUT -p tcp --dport 80 -i wan0 -j DROP
iptables -I INPUT -p tcp --dport 443 -i wan0 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.