CVE-2026-104610: 12,055 Tenda gateways exposed to the internet
CVE-2026-104610 affects Tenda HG7, HG9 and HG10 fibre gateways. A ZoomEye fingerprint query found 12,055 internet-reachable devices, while a title-based search returned 426,677 matches that mostly include shop pages and documentation.
- CVE-2026-104610 affects Tenda HG7, HG9 and HG10 gateways
- ZoomEye app="Tenda" query returned 12,055 hosts vs 426,677 for title="Tenda"
- The exploit is public and needs no authentication
- Attack signature: requests to /boaform/formLoopBack with a long Ethtype value
Read next
Security