A vulnerability categorized as critical has been discovered in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function
formDOMAINBLK of the file /boaform/formDOMAINBLK. Executing a manipulation of the argument blkDomain can lead to stack-based buffer overflow.
This vulnerability appears as CVE-2026-11499. The attack may be performed from remote. There is no available exploit.