CVE detail
CVE-2026-11553
A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- https://www.tenda.com.cn/www.tenda.com.cn
No excerpt available.
Release Noteswww.tenda.com.cnJun 8, 2026, 6:16 PM - https://vuldb.com/vuln/369163/ctivuldb.com
No excerpt available.
Exploitvuldb.comJun 8, 2026, 6:16 PM - https://vuldb.com/vuln/369163vuldb.com
No excerpt available.
Exploitvuldb.comJun 8, 2026, 6:16 PM - https://vuldb.com/submit/836778vuldb.com
No excerpt available.
Exploitvuldb.comJun 8, 2026, 6:16 PM - https://vuldb.com/cve/CVE-2026-11553vuldb.com
No excerpt available.
Exploitvuldb.comJun 8, 2026, 6:16 PM No excerpt available.
Exploitgithub.comJun 8, 2026, 6:16 PMNo excerpt available.
Exploitgithub.comJun 8, 2026, 6:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16248CVSS 7.4 · High
A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. Th…
- CVE-2026-16097CVSS 8.7 · High
A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 re…
- CVE-2026-16096CVSS 8.7 · High
A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads…
- CVE-2026-15701CVSS 8.9 · High
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd.…
- CVE-2026-15696CVSS 7.4 · High
A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the file /goform/VirtualSer. Such manipulation of the argument…
- CVE-2026-15695CVSS 7.4 · High
A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument…