Description
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-08-16
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the R7WebsSecurityHandler component of the httpd service on Tenda AC10 firmware 16.03.10.09_multi_TDE01 allows remote attackers to bypass authentication. The vulnerability is a classic improper authentication issue (CWE-287) that can give an attacker full administrative access to the device’s web interface, enabling configuration changes, content manipulation, or further lateral movement.

Affected Systems

Tenda AC10 firmware version 16.03.10.09_multi_TDE01, specifically the httpd component

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. The EPSS score is not available, but a publicly disclosed exploit suggests a high chance of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalogue, meaning it may not yet have widespread awareness. An attacker who can reach the device’s management interface can exploit the flaw remotely, bypass authentication, and gain full control, potentially compromising the device and any network assets attached to it.

Generated by OpenCVE AI on August 16, 2026 at 02:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update that fixes the R7WebsSecurityHandler authentication issue.
  • If no update is available, disable or block the device’s HTTP/HTTPS management interface, or restrict it to a trusted local subnet using firewall or ACL rules.
  • Change any default or weak credentials on the web interface and enforce a strong password policy.

Generated by OpenCVE AI on August 16, 2026 at 02:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 16 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Title Tenda AC10 httpd R7WebsSecurityHandler improper authentication
First Time appeared Tenda
Tenda ac10 Firmware
Weaknesses CWE-287
CPEs cpe:2.3:o:tenda:ac10_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda ac10 Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Tenda Ac10 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-16T01:00:13.158Z

Reserved: 2026-08-15T05:24:58.354Z

Link: CVE-2026-19924

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-16T02:16:47.247

Modified: 2026-08-16T02:16:47.247

Link: CVE-2026-19924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-16T02:30:16Z

Weaknesses