CVE-2026-5548 is a high-severity (CVSS 8.8) stack-based buffer overflow vulnerability affecting the Tenda AC10 16.03.10.10_multi_TDE01 router, specifically within the fromSysToolChangePwd function of the /bin/httpd file. A remote attacker can exploit this by manipulating the sys.userpass argument, potentially leading to full compromise of the device's confidentiality, integrity, and availability. Although no public exploit code (Metasploit, Nuclei, ExploitDB) or KEV entry exists, the vulnerability is listed on the "Hot List" and has garnered community discussion, indicating potential interest for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.03.10.10_multi_tde01CPE matchmatch criteria | cpe:2.3:o:tenda:ac10_firmware:16.03.10.10_multi_tde01:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.