Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.9

CVE-2026-19924: Tenda AC10 httpd: Remote Authentication Bypass Possible

CVE-2026-19924 · published 19 days ago
Summary

A security issue in the Tenda AC10 router's web server could allow an attacker to bypass authentication remotely. This could potentially give the attacker access to the router's settings or other sensitive information. Users should update their Tenda AC10 routers to the latest available software version to fix this issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
tenda ac10 16.03.10.09_multi_TDE01
Original advisory text
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to imp...
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Severity
8.9 High
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published16 Aug 2026
Updated3 Sep 2026
First seen16 Aug 2026
Sources
CVE-2026-19924 · MITRE
Monitor software like this
Free during beta