426,677 titles against 12,055 fingerprints: locating the Tenda gateways behind CVE-2026-104610
426,677 titles against 12,055 fingerprints: locating the Tenda gateways behind CVE-2026-104610 CVE-2026-104610 affects the Tenda HG7, HG9 and HG10 fibre gateways. Finding them from outside is harder than the headline severity suggests, because the obvious query and the accurate query return very different populations. What we measured Two queries were run against ZoomEye on 2026-10-04 (UTC), both…
A vulnerability, CVE-2026-104610, affects three Tenda fibre gateways: the HG7, HG9, and HG10. Locating these devices on the internet is more challenging than the headline severity might suggest due to the discrepancy between the search results for titles containing "Tenda" and the application fingerprint assigned to the devices.
Two queries were performed on ZoomEye on 2026-10-04 (UTC), both with a page size of one. The title search returned 426,677 matches, while the application fingerprint search returned 12,055 matches. The title search includes not only the manufacturer's product pages and router interfaces but also documentation mirrors. In contrast, the application fingerprint is a more accurate representation of the affected devices.
The title-based search is unreliable due to the noisy nature of consumer networking brands. Device interfaces are often titled with generic login strings or model numbers rather than the brand name. Therefore, the title query overcounts non-devices and undercounts real ones. The 12,055 figure, although still useful, establishes that a significant population of Tenda-fingerprinted assets is reachable from the internet, which is a prerequisite for remote exploitation of the vulnerability. It also sets an expectation for the scale of a coordinated response.
The remediation for CVE-2026-104610 does not depend on the count. The most critical step is to close the exposure where a vulnerable HG7, HG9, or HG10 is reachable on its management interface from the WAN side. Restricting management to an administrative VLAN and removing the WAN-side listener are effective controls, regardless of whether Tenda releases a fix. Detection is also possible through alerts on requests to /boaform/formLoopBack with an unusually long Ethtype value.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.