Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.9
CVE-2026-19924: Tenda AC10 httpd: Remote Authentication Bypass Possible
CVE-2026-19924 · published 19 days ago
Summary
A security issue in the Tenda AC10 router's web server could allow an attacker to bypass authentication remotely. This could potentially give the attacker access to the router's settings or other sensitive information. Users should update their Tenda AC10 routers to the latest available software version to fix this issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| tenda | ac10 | 16.03.10.09_multi_TDE01 |
Original advisory text
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to imp...
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
References
- https://vuldb.com/vuln/390174 vdb-entry technical-description
- https://vuldb.com/vuln/390174/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-19924 third-party-advisory
- https://vuldb.com/submit/871957 third-party-advisory
- https://github.com/teiwiet/tenda-ac10-vulnerabilities/blob/main/authen-bypass-te... exploit
- https://www.tenda.com.cn/ product
Severity
8.9
High
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published16 Aug 2026
Updated3 Sep 2026
First seen16 Aug 2026
Monitor software like this
Free during beta