Executive brief
A vulnerability exists in the Tenda AC10 router, a device used to provide wireless internet connectivity for homes and small offices. An attacker with valid login credentials can exploit this flaw to take complete control of the router. This could allow them to intercept internet traffic, disrupt network services, or use the device as a foothold to attack other devices on the local network.
Technical details
An OS command injection vulnerability exists in the Tenda AC10 router firmware version 16.03.10.10_multi_TDE01. The flaw is located within the 'formAddMacfilterRule' function (and approximately 20 other functions) in the '/bin/httpd' binary. The root cause is the improper neutralization of user-supplied input from 'websGetVar()' before it is passed to 'doSystemCmd()', which executes shell commands. An authenticated attacker can exploit this over the network by sending crafted requests to the affected endpoints. Successful exploitation results in arbitrary command execution with root-level privileges. No official patch is currently detailed in the advisory, though remediation suggests sanitizing shell metacharacters and using allowlist validation.
Affected products
- Tenda AC10 16.03.10.10_multi_TDE01
Timeline
- 2026-04-05: disclosed: Initial disclosure via VulDB and NVD
- 2026-04-05: advisory