## https://sploitus.com/exploit?id=2539C5BF-0E4B-5CED-A482-A999695CCB13
# Tenda HG10 Stack-based Buffer Overflow Vulnerability
## Summary
A stack-based buffer overflow vulnerability exists in the formDOMAINBLK interface via the blkDomain parameter exposed through the web management interface /boaform/formDOMAINBLK of the Tenda HG10 router.
## Vendor
Tenda
## Product
HG10
## Affected Version
HG7_HG9_HG10re_300001138_en_xpon
## Vulnerability Type
Stack-based Buffer Overflow
## Affected Interface
/boaform/formDOMAINBLK
## Affected Function
formDOMAINBLK
## Affected Parameter
blkDomain
## Description
A stack-based buffer overflow vulnerability exists in the formDOMAINBLK interface via the blkDomain parameter exposed through the web management interface /boaform/formDOMAINBLK of the Tenda HG10 router.
The vulnerable code copies user-controlled blkDomain input into a stack buffer without effective length validation, which may overwrite the stack frame.
## Impact
An unauthenticated attacker with access to the web management interface may be able to trigger a denial of service by crashing the Boa web service or potentially execute arbitrary code depending on the runtime environment and protections.
## Disclosure
This vulnerability is submitted through VulDB for CVE assignment.
## Assets
Relevant screenshots and supporting materials are stored in the assets directory.