Impact
A flaw in the formAddMacfilterRule handler of /bin/httpd in Tenda AC10 firmware 16.03.10.10_multi_TDE01 allows an attacker to inject arbitrary system commands through manipulated input. This results in command injection that can be executed with the privileges of the httpd process, potentially providing full control over the device.
Affected Systems
The vulnerability is specific to Tenda AC10 routers running firmware 16.03.10.10_multi_TDE01, as identified by the vendor and the associated CPE string. All configuration endpoints that expose the formAddMacfilterRule function may be impacted; no other products have been reported to be affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely via the device’s web management interface. Once leveraged, an attacker could execute commands on the router, compromising confidentiality, integrity, and availability of the device. Because the vulnerability remains publicly known and no patch is cited in the advisory, the risk persists for any exposed router.
OpenCVE Enrichment