CVE-2026-11499
A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK. Executing a manipulation of the argument blkDomain can lead to stack-based buffer overflow. The attack may be performed from remote.
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 6.6% (93th percentile)
- Weakness
- CWE-119, CWE-121
- NVD status
- Deferred
- Published
- 2026-06-08
CVE-2026-11499 at NVD
4 known exploits for CVE-2026-11499
Proof-of-concept code and exploit modules indexed by Sploitus