Skip to main content

Vendor/product archive

tenda / ac10_firmware CVEs

Beta · best-effort

92 CVEs tagged to tenda / ac10_firmware44 Critical, 31 High, 16 Medium, 1 Low, 0 Unrated.

CVE-2026-5550

Published Apr 5, 2026

A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based…

CVSS 8.7 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-5549

Published Apr 5, 2026

A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the compon…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-5548

Published Apr 5, 2026

A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulat…

CVSS 8.7 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-5547

Published Apr 5, 2026

A vulnerability has been found in Tenda AC10 16.03.10.10_multi_TDE01. Affected is the function formAddMacfilterRule of the file /bin/httpd. Such manipulation leads to os command i…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-67074

Published Dec 17, 2025

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code ex…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67073

Published Dec 17, 2025

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code ex…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-12622

Published Nov 3, 2025

A vulnerability was determined in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd of the file /goform/SysRunCmd. This manipulation of the argu…

CVSS 7.4 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2025-57220

Published Aug 28, 2025

An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privileges to root via a crafted UDP packet.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57219

Published Aug 28, 2025

Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attackers to escalate privileges or access sensitive components vi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57218

Published Aug 28, 2025

Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g parameter in the function sub_46284C.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57217

Published Aug 28, 2025

Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the Password parameter in the function R7WebsSecurityHandler.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-9309

Published Aug 21, 2025

A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the component MD5 Hash Handler. Performing manipulation results…

CVSS 1.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-8178

Published Jul 26, 2025

A vulnerability classified as critical has been found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /goform/RequestsProcessLaid. The manipulation of the a…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-5629

Published Jun 5, 2025

A vulnerability, which was classified as critical, was found in Tenda AC10 up to 15.03.06.47. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg of t…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-4896

Published May 18, 2025

A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/UserCongratulationsExec. T…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 92 CVEsPage 1 of 4