Executive brief
A security vulnerability has been identified in the Tenda AC10 router, a device used to provide wireless internet connectivity. An attacker could exploit this flaw to crash the router or potentially take full control of the device by sending specially crafted data. This could lead to a complete loss of internet availability or unauthorized access to network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the 'fromSysToolChangePwd' function within the '/bin/httpd' binary of Tenda AC10 firmware version 16.03.10.10_multi_TDE01. The root cause is an unbounded copy operation where the 'GetValue' function retrieves the 'sys.userpass' argument into a fixed-size 36-byte stack buffer without length validation. A remote attacker with the ability to manipulate this NVRAM value (potentially through chained exploitation of other vulnerabilities) can overflow the buffer to overwrite the saved return address ($ra). This can lead to arbitrary code execution or a denial-of-service condition.
Affected products
- Tenda AC10 16.03.10.10_multi_TDE01
Timeline
- 2026-04-05: disclosed: Initial disclosure via VulDB and NVD
- 2026-04-05: advisory