CVE-2026-5550
8.8Tenda · AC10
A stack-based buffer overflow in the Tenda AC10 /bin/httpd service allows remote attackers to trigger memory corruption via the fromSysToolChangePwd function.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda AC10 firmware version 16.03.10.10_multi_TDE01 presents a severe risk of remote code execution.
Vulnerability
The vulnerability exists in the fromSysToolChangePwd function within the /bin/httpd binary. An authenticated attacker can trigger a stack-based buffer overflow, potentially leading to arbitrary code execution or service disruption.
Business impact
The CVSS score of 8.8 indicates a high severity rating, reflecting the potential for total loss of confidentiality, integrity, and availability of the affected router. Exploitation of this flaw could allow an attacker to gain unauthorized control over network infrastructure, facilitating further lateral movement within the corporate environment or interception of sensitive traffic.
Remediation
Immediate Action: Since a specific patch is currently unknown, administrators should restrict access to the web management interface to trusted internal networks only. If possible, disable remote management features until the vendor provides a firmware update.
Proactive Monitoring: Monitor device logs for unusual crashes of the /bin/httpd process or repeated failed login attempts that might indicate exploitation reconnaissance.
Compensating Controls: Deploy network segmentation to isolate the affected Tenda devices from critical internal assets and utilize a firewall to block unauthorized access to the router management port.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the high CVSS score and the nature of the buffer overflow, this vulnerability poses a significant risk to network security. Administrators must prioritize the isolation of the Tenda AC10 management interface immediately and monitor official Tenda support channels for the release of a patched firmware version.
More Tenda CVEs
Sources
Originally found and disclosed by CoreNode (VulDB User), per the CVE Program record.