CVE-2026-11499
A critical vulnerability in Tenda HG7HG9 and HG10 routers allows remote attackers to trigger a stack-based buffer overflow by sending a crafted request to the formDOMAINBLK endpoint. This flaw could enable attackers to execute arbitrary code on the device.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Tenda HG7HG9 and HG10 300001138_en_xpon routers.
Real-world impact
An attacker could take control of the router, intercept or modify traffic, and disrupt network services.
Why this severity
The CVSS score of 9.3 reflects that the flaw can be exploited remotely without authentication, and it can compromise confidentiality, integrity, and availability of the device.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jun 8, 2026 · Jun 8, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.