CVE-2026-11553
Tenda HG7HG9/HG10 formPPPEdit stack-based overflow
- Published
- Jun 8, 2026
- Updated
- Jun 8, 2026
- Assigning CNA
- VulDB
- Evidence observed
- Aug 25, 2026
Tenda HG7HG9/HG10 formPPPEdit stack-based overflow
nvd · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XLow · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
Deployed patch for CVE-2026-11553, an authentication bypass vulnerability in VMware vCenter, with validation and deployment details for production environments.
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.