Stack-Based Buffer Overflow in Tenda AC10 by Tenda
CVE-2026-5548
8.7HIGH
What is CVE-2026-5548?
A stack-based buffer overflow vulnerability exists in the Tenda AC10 router, specifically within the fromSysToolChangePwd function of the /bin/httpd file. An attacker can exploit this vulnerability by manipulating the sys.userpass argument, allowing for potential remote code execution. It's crucial for users of the Tenda AC10 to ensure their devices are updated to mitigate the risks associated with this security flaw.
Affected Version(s)
AC10 16.03.10.10_multi_TDE01