Impact
This flaw is a stack or heap buffer overflow located in the /cgi-bin/UploadCfg endpoint of Tenda AC10 v3 firmware V03.03.16.09. The overflow arises from an unchecked write that corrupts memory, allowing an attacker to execute arbitrary code or cause a permanent denial of service. It is classified as CWE‑120: Vulnerable Buffer Copy without Checking Size or Overrun.
Affected Systems
The vulnerability affects consumer routers manufactured by Tenda, specifically the AC10 v3 model running firmware V03.03.16.09. Firmware upgrades that do not include the patch leave the device exposed; newer releases may resolve the issue, but the information is not currently available.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of < 1% shows a very low probability of exploitation at present, and the flaw is not listed in the CISA KEV catalog. Nevertheless, the attack vector is remote, triggered by an HTTP POST to the UploadCfg path, meaning any network‑connected attacker can attempt the overflow and potentially achieve code execution.
OpenCVE Enrichment