CVE-2026-5550 identifies a stack-based buffer overflow in the fromSysToolChangePwd function of the /bin/httpd component in Tenda AC10 routers, specifically firmware version 16.03.10.10_multi_TDE01. This high-severity vulnerability (CVSS 8.8) allows for remote exploitation with low privileges and no user interaction, potentially leading to complete compromise of the device, including remote code execution. While not currently listed in CISA's KEV, it is on the 'Hot List: Active' and has generated community discussion regarding its severe impact potential. No public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.03.10.10_multi_tde01CPE matchmatch criteria | cpe:2.3:o:tenda:ac10_firmware:16.03.10.10_multi_tde01:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.