HIGHVulnerability

CVE-2026-86166

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Properties

severity
HIGH
score
8.8
cve_id
CVE-2026-86166
signal_observed_at
2026-09-16T21:37:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-09-06T04:18:32.783
last_modified
2026-09-11T21:17:35.040

Related Entities (3)

HAS_WEAKNESS (2)

[Weakness]Improper Restriction of Operations within the Bounds of a Memory Buffer
[Weakness]Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86166 — Ninja Signal Threat Intelligence | Ninja Signal