CVE-2026-85109 is a buffer overflow vulnerability in the formLogin function of the Boa web server component in Tenda HG10 firmware version 300001138. Remote, unauthenticated attackers can send a crafted Username parameter to /boaform/formLogin to overflow a fixed-size buffer, with confirmed denial-of-service impact and potential for remote code execution. The exploit has been publicly disclosed.
