CVE-2026-19924

9.8

Tenda · AC10

The Tenda AC10 router is vulnerable to an authentication bypass in the `R7WebsSecurityHandler` function, allowing unauthenticated remote attackers to gain unauthorized access.

Executive summary

An authentication bypass vulnerability in the Tenda AC10 router allows unauthenticated remote attackers to gain administrative access to the device.

Vulnerability

The httpd component contains an improper authentication flaw in the R7WebsSecurityHandler function. This flaw can be triggered remotely by an unauthenticated attacker to bypass security controls.

Business impact

An attacker gaining administrative access to a router can intercept network traffic, modify DNS settings to redirect users to malicious sites, or use the device as a pivot point for further attacks on the internal network. The CVSS score of 9.8 reflects the high potential for unauthorized access and network-wide compromise.

Remediation

Immediate Action: Check the Tenda support website for firmware updates addressing this authentication issue.

Proactive Monitoring: Monitor router logs for unauthorized login attempts or unexpected configuration changes.

Compensating Controls: Disable remote management interfaces on the WAN side to prevent external access to the device's web management console.

Exploitation status

Public Exploit Available: Yes — a public exploit has been disclosed via a GitHub repository.

Analyst recommendation

The existence of a public exploit significantly increases the risk to Tenda AC10 devices. Administrators should ensure that remote management is disabled immediately and apply the latest firmware update as soon as it becomes available from the manufacturer. Failure to secure the device may result in full network compromise.

More Tenda CVEs