Share
## https://sploitus.com/exploit?id=276C3345-B0C7-5080-9153-F78548A9B10D
# Tenda HG10 Stack-based Buffer Overflow Vulnerability

## Summary

A stack-based buffer overflow vulnerability exists in the asp_voip_OtherSet interface via the funckey_transfer parameter exposed through the web management interface /boaform/voip_other_set of the Tenda HG10 router.

## Vendor

Tenda

## Product

HG10

## Affected Version

HG7_HG9_HG10re_300001138_en_xpon

## Vulnerability Type

Stack-based Buffer Overflow

## Affected Interface

/boaform/voip_other_set

## Affected Function

asp_voip_OtherSet

## Affected Parameter

funckey_transfer

## Description

A stack-based buffer overflow vulnerability exists in the asp_voip_OtherSet interface via the funckey_transfer parameter exposed through the web management interface /boaform/voip_other_set of the Tenda HG10 router.

## Impact

An attacker with access to the web management interface may be able to trigger a denial of service or potentially execute arbitrary code depending on the runtime environment and protections.

## Disclosure

This vulnerability is submitted through VulDB for CVE assignment.

## Assets

Relevant screenshots and supporting materials are stored in the assets directory.