Executive brief
A vulnerability exists in the Tenda AC10 router's web management interface. An authenticated attacker can send specially crafted network configuration data that exceeds the device's memory limits. This can lead to a complete system crash or allow the attacker to gain unauthorized control over the router, potentially compromising the security of the entire local network.
Technical details
A stack-based buffer overflow exists in the Tenda AC10 (firmware 16.03.10.09_multi_TDE01) within the 'fromAdvSetLanip' handler of the httpd/netctrl component. The vulnerability is caused by a lack of length validation when storing configuration values (such as LAN IP or DNS fields) via SetValue, which accepts up to 1499 bytes. When these values are subsequently retrieved via GetValue, the backend routine 'cfms_mib_proc_handle' uses the source string length as the bound for a strncpy operation into fixed-size stack buffers (e.g., 8 or 16 bytes). An authenticated attacker can exploit this by persisting an oversized configuration value, which triggers memory corruption and a process crash when the value is read back. The exploit has been made public.
Affected products
- Tenda AC10 V4.0 16.03.10.09_multi_TDE01
Timeline
- 2026-07-20: disclosed: CVE published to NVD