cbcvebase.

Tenda Hg7Hg9 vulnerabilities

3 known vulnerabilities affecting tenda/hg7hg9.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2

Vulnerabilities

Page 1 of 1
CVE-2026-11499P2CRITICALCVSS 9.8v300001138_en_xpon2026-06-08
CVE-2026-11499 [CRITICAL] CWE-119 CVE-2026-11499: A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK. Executing a manipulation of the argument blkDomain can lead to stack-based buffer overflow. The attack may be performed from remote.
nvd
CVE-2026-11498P2HIGHCVSS 8.8v300001138_en_xpon2026-06-08
CVE-2026-11498 [HIGH] CWE-119 CVE-2026-11498: A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of the argument funckey_transfer results in stack-based buffer overflow. The attack is possible to be carried out remotely
nvd
CVE-2026-11553P2HIGHCVSS 8.8v300001138_en_xpon2026-06-08
CVE-2026-11553 [HIGH] CWE-119 CVE-2026-11553: A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function form A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
nvd
Tenda Hg7Hg9 vulnerabilities | cvebase