Executive brief
A vulnerability exists in the Tenda AC10 v3.0 router, a device used to provide wireless internet access. By uploading a specially crafted configuration file, an attacker can cause the router to enter a permanent 'brick' state where it becomes completely unresponsive and cannot be fixed using the physical reset button. This results in a permanent loss of internet connectivity and requires hardware-level repairs or replacement of the device.
Technical details
A stack-based buffer overflow exists in the Tenda AC10 v3.0 (firmware V03.03.16.09) within the configuration restoration mechanism. The vulnerability is located in the /cgi-bin/UploadCfg endpoint, which fails to properly validate the length of user-supplied strings before passing them to the internal nvram_set function (specifically via FUN_80047190). Although the router attempts to verify configuration integrity, it uses a weak ASCII summation checksum that is easily bypassed. An attacker can provide an oversized string for parameters like 'wan0_macclone_mode', leading to memory corruption. Because the corrupted configuration is stored in NVRAM and processed early in the boot cycle, the device enters an infinite crash loop (bootloop) that occurs before GPIO handlers are initialized, rendering the physical reset button non-functional. As of the advisory date, the vendor has not provided a patch.
Affected products
- Tenda AC10 v3.0 V03.03.16.09
Timeline
- 2026-03-27: disclosed: Vulnerability discovered by researcher
- 2026-07-15: advisory: Public disclosure after 60-day non-responsive period