Telecommunications security researchers and vulnerability coordinators have disclosed a critical stack-based buffer overflow flaw in Tenda GPON Optical Network Terminals (ONT) (cataloged as CVE-2026-104610, CVSS 9.8). The vulnerability allows unauthenticated attackers situated on the WAN or local network interface to transmit crafted HTTP packets, hijack MIPS processor control registers, and achieve persistent root-level remote code execution across edge fiber routing infrastructure.
Hardware Architecture & Memory Corruption Breakdown
Tenda GPON terminals (commonly deployed by telecommunications service providers as customer premises equipment to bridge optical fiber gigabit networks with local Ethernet LANs) utilize an embedded Linux operating system running on MIPS32 architecture. Remote administration and local device configuration are handled by an embedded HTTP daemon derived from the GoAhead web server.
The vulnerability exists within the firmware's asp_check_auth parsing routine. When an incoming HTTP request containing a Cookie or Authorization header is received, the binary extracts token values and copies them into a fixed-size 256-byte stack buffer using the unsafe C standard library function strcpy() without boundary validation:
// Decompiled firmware excerpt from /bin/goahead web daemon
int asp_check_auth(webs_t wp, char_t *url) {
char cookie_buf[256];
char *cookie_header = websGetVar(wp, "HTTP_COOKIE", "");
if (cookie_header && *cookie_header) {
// INSECURE: Unchecked copy into stack buffer leads to buffer overflow
strcpy(cookie_buf, cookie_header);
return validate_session_token(cookie_buf);
}
return AUTH_REQUIRED;
}
By transmitting an HTTP request containing a cookie header exceeding 280 bytes, an attacker corrupts adjacent stack variables, overwrites the saved return address register ($ra), and gains direct control over processor execution flow upon function return.
Exploitation Mechanics on Embedded MIPS32
Because legacy embedded MIPS Linux toolchains frequently omit stack canaries (-fstack-protector) and Position Independent Executables (PIE), and because Address Space Layout Randomization (ASLR) is disabled or non-existent in these firmware kernels, exploit payloads are highly reliable. An attacker crafts a payload containing:
- Padding bytes to fill the local 256-byte stack frame.
- A target return address pointing to an existing Return-Oriented Programming (ROP) gadget in
libuClibc.so. - MIPS shellcode crafted to invoke
system()or bind a root shell to a specified TCP port.
# Proof-of-concept trigger against vulnerable GPON terminal endpoint
curl -X GET "http://target-gpon-device/index.asp" -H "Cookie: session_id=$(python3 -c 'print("A"*268 + "4" + "$E...")')" --connect-timeout 5
Firmware Impact & Attack Surface
| Model Family | Impacted Firmware Builds | Primary Exploitation Vector | Impact |
|---|---|---|---|
| Tenda G3 / G1 GPON Series | Firmware < v1.0.0.18 | WAN / LAN Web Port (80 / 8080) | Root Remote Code Execution |
| Tenda HG Series (HG9 / HG6) | Firmware < v2.1.0.8 | TR-069 / CWMP & HTTP Services | Device Takeover & Traffic Snooping |
| Tenda AC Series Hybrid ONTs | All unpatched releases | Web Administration Interface | Full Infrastructure Pivot |
Defensive Remediation Playbook
- Deploy Vendor Firmware Updates: Update all deployed Tenda GPON ONTs to the latest official firmware releases that replace unsafe memory routines with bounded equivalents (
strncpy/strlcpy). - Disable Remote WAN Management: Reconfigure access control lists (ACLs) to strictly prohibit HTTP/HTTPS administration access over public WAN optical interfaces:
# Recommended ONT Access Control Rules: WAN_MANAGEMENT_ACCESS: DISABLED LAN_MANAGEMENT_SUBNET: 192.168.1.0/24 (Restricted VLAN only) TR069_CWMP_INTERFACE: ISOLATED_MANAGEMENT_VLAN_ONLY - Implement ISP-Level Filtering: Broadband telecom operators should filter inbound traffic to ports
80,8080, and443directed at customer CPE WAN IPs to shield vulnerable modems from global automated worm scans.



