Impact
A flaw in the R7WebsSecurityHandler component of the httpd service on Tenda AC10 firmware 16.03.10.09_multi_TDE01 allows remote attackers to bypass authentication. The vulnerability is a classic improper authentication issue (CWE-287) that can give an attacker full administrative access to the device’s web interface, enabling configuration changes, content manipulation, or further lateral movement.
Affected Systems
Tenda AC10 firmware version 16.03.10.09_multi_TDE01, specifically the httpd component
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The EPSS score is not available, but a publicly disclosed exploit suggests a high chance of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalogue, meaning it may not yet have widespread awareness. An attacker who can reach the device’s management interface can exploit the flaw remotely, bypass authentication, and gain full control, potentially compromising the device and any network assets attached to it.
OpenCVE Enrichment