Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2026-11499 – Unauthenticated Stack-Based Buffer Overflow (RCE) – Tenda HG7, HG9, and HG10 Fir…

Be the first to know when new zero-days emerge:

Summary

CVE-2026-11499 is a critical-severity stack-based buffer overflow in the formDOMAINBLK function of Tenda HG7, HG9, and HG10 xPON ONT router devices running firmware version 300001138_en_xpon. The flaw is remotely exploitable without any authentication or user interaction, carrying a CVSS 4.0 score of 9.3 (Critical), and constitutes an effective unauthenticated remote code execution primitive with full device compromise potential. No official vendor patch has been published at the time of this writing.

Technical details

  • Root cause: Insufficient bounds checking on user-supplied input in the formDOMAINBLK function served at the /boaform/formDOMAINBLK endpoint of the Boa embedded web server. Manipulation of the blkDomain argument overflows a fixed-size stack buffer.
  • Trigger conditions: A remote, unauthenticated attacker sends a crafted HTTP request to /boaform/formDOMAINBLK with an oversized or maliciously crafted blkDomain parameter value, triggering the stack overflow.
  • Attack vector: Network-accessible (AV:N), no authentication required (PR:N), no user interaction required (UI:N), low attack complexity (AC:L). The management interface runs on the Boa embedded HTTP server, which is fingerprint-identifiable via the Server response header.
  • Impact: High impact to confidentiality, integrity, and availability — consistent with arbitrary code execution on the underlying device. Full device takeover, persistent access, and lateral movement within the connected network are plausible outcomes.
  • Vulnerability class context: Multiple concurrent CVEs have been disclosed against the same firmware (300001138_en_xpon) across the same device family, indicating active researcher focus on this firmware. Related vulnerabilities include stack-based overflows in other /boaform/ endpoints and command injection flaws, confirming the breadth of the attack surface on these devices.

Affected software

  • Tenda HG7 — firmware version 300001138_en_xpon
  • Tenda HG9 — firmware version 300001138_en_xpon
  • Tenda HG10 — firmware version 300001138_en_xpon

Severity

CVSS 4.0 Base Score: 9.3 (Critical)
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X

Mitigation and recommended actions

  • No official patch has been released by Tenda for CVE-2026-11499 at the time of publication. Monitor Tenda’s firmware download center for security updates addressing this firmware line.
  • Immediate network mitigation: Restrict all inbound access to the device’s HTTP management interface (port 80) to trusted IP ranges only. Block internet-facing exposure of the /boaform/ endpoint at the network perimeter or firewall level.
  • Disable WAN-side management: Where device configuration permits, ensure the Boa web management interface is not accessible from the WAN/internet. These devices are xPON ONT CPE routers typically administered via LAN or TR-069; WAN-facing management exposure is not required for normal operation.
  • ISP/MSP guidance: Organizations or ISPs deploying these devices to end users should audit whether management interfaces are reachable externally and enforce isolation policies accordingly.

IONIX Status

The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

References

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge