CVE-2026-11499

🟠 Łataj w tym tygodniu

Przepełnienie bufora w Tenda HG7HG9 i HG10 umożliwia zdalne wykonanie kodu.

CVSS
9.8
EPSS
6.6%
Exploit
none
Vendor
Opis źródłowy (NVD)

A vulnerability was determined in Tenda HG7, HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK. Executing a manipulation of the argument blkDomain can lead to stack-based buffer overflow. The attack may be performed from remote.

buffer-overflow Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)6.6%
Opublikowano (NVD)2026-06-08 09:16:29 UTC
Ostatnia modyfikacja (NVD)2026-10-02 04:18:05 UTC
Referencje