Executive brief
A security vulnerability has been identified in the Tenda AC10 router, a device used to provide wireless internet in homes and small offices. An attacker could exploit this flaw to crash the router or potentially take full control of the device. This could lead to unauthorized access to the network, interception of internet traffic, or a complete loss of internet connectivity for the user.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda AC10 router (firmware version 16.03.10.10_multi_TDE01) within the 'fromSysToolChangePwd' function of the /bin/httpd binary. The root cause is a systemic failure in the 'GetValue()' API, which retrieves configuration values from NVRAM and copies them into fixed-size stack buffers (ranging from 16 to 64 bytes) without length validation. An attacker with network access and low-level privileges can trigger this overflow by providing oversized values. Because the binary lacks stack canaries and Address Space Layout Randomization (ASLR), this vulnerability can be reliably exploited for remote code execution. Static analysis indicates over 200 other call sites may be similarly affected.
Affected products
- Tenda AC10 16.03.10.10_multi_TDE01
Timeline
- 2026-04-05: disclosed: Vulnerability first reported/published
- 2026-04-05: advisory