CVE-2026-11499 is a remotely triggerable stack-based buffer overflow affecting Tenda HG7, HG9, and HG10 devices running firmware 300001138_en_xpon. Manipulation of the blkDomain argument handled by the formDOMAINBLK function can trigger the overflow. Potential consequences include a device crash or arbitrary code execution, but these downstream outcomes have not been established.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal two-file proof-of-concept for CVE-2026-11499 affecting Tenda HG7/HG9/HG10 routers. The code consists of a single Python script, CVE-2026-11499.py, plus a README describing the vulnerability at a high level. The exploit is not part of a larger framework and is focused solely on sending a crafted HTTP POST request to the router web interface. The PoC’s core capability is denial-of-service testing via a suspected stack-based buffer overflow in the /boaform/formDOMAINBLK handler. It constructs an oversized blkDomain form value using repeated 'A' characters and submits it with additional fields (submit-url=/domainblk.asp and page=domainblk) and a Referer header pointing to /domainblk.asp. The script interprets HTTP timeout or connection failure as evidence that the router or web service crashed. An optional incremental mode increases payload size from 100 to 950 bytes in 50-byte steps to help identify an approximate crash threshold. There is no authentication bypass, shellcode delivery, reverse shell, RCE chain, persistence, or post-exploitation logic. Although the README mentions potential RCE conceptually, the actual code only demonstrates crash-oriented behavior and should be classified as a PoC DoS exploit rather than a weaponized RCE exploit. The repository structure is straightforward: one executable Python entry point and one documentation file. The main fingerprintable targets are the router management paths /boaform/formDOMAINBLK and /domainblk.asp, along with the blkDomain parameter used as the overflow vector.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remotely reachable stack-based buffer overflow in Tenda HG7HG9 and HG10 firmware 300001138_en_xpon, triggered by manipulating the blkDomain argument in the formDOMAINBLK function at /boaform/formDOMAINBLK. The content does not specify authentication requirements or the resulting impact beyond the buffer overflow.
A remote stack-based buffer overflow vulnerability in the formDOMAINBLK function of /boaform/formDOMAINBLK affecting Tenda HG7HG9 and HG10 devices running firmware 300001138_en_xpon.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.