Stack-Based Buffer Overflow in Tenda AC10 by Tenda
CVE-2026-5548
8.7HIGH
What is CVE-2026-5548?
A stack-based buffer overflow vulnerability exists in the Tenda AC10 router, specifically within the fromSysToolChangePwd function of the /bin/httpd file. An attacker can exploit this vulnerability by manipulating the sys.userpass argument, allowing for potential remote code execution. It's crucial for users of the Tenda AC10 to ensure their devices are updated to mitigate the risks associated with this security flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AC10 16.03.10.10_multi_TDE01