Sceawere

Vulnerability Detail

CVE-2026-19924UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Tenda AC10 Improper Authentication Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
Tenda
Product
AC10
Attack Type
Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-16T02:16:47.247Z",
  "pubdate": "2026-08-16T02:16:47.247Z",
  "executiveSummary": "A critical security vulnerability has been identified in the Tenda AC10 router running firmware version 16.03.10.09_multi_TDE01. The vulnerability resides within the httpd component, specifically affecting the R7WebsSecurityHandler function. This security flaw involves an improper authentication vulnerability that can be exploited remotely by malicious actors over the network without requiring prior authentication or user interaction.\nThe successful exploitation of this vulnerability compromises the security posture of the targeted Tenda AC10 device, potentially allowing unauthorized remote attackers to bypass security controls and access restricted functionality handled by the httpd web server. Given that an exploit has been disclosed publicly, the risk of active exploitation in the wild is elevated.\nOrganizations and individual users utilizing the affected Tenda AC10 firmware version face significant risk of unauthorized access and potential control over network infrastructure devices. Immediate remediation or mitigating controls are strongly advised to thwart remote exploitation attempts.",
  "technicalDetails": "The vulnerability stems from an improper authentication implementation within the httpd binary of the Tenda AC10 firmware version 16.03.10.09_multi_TDE01. Specifically, the flaw is located inside the R7WebsSecurityHandler function, which is responsible for evaluating security constraints, handling session validations, and enforcing access control policies for incoming HTTP requests processed by the embedded web server.\nRoot cause analysis indicates that the R7WebsSecurityHandler function fails to adequately verify credentials or validate security tokens under specific request conditions. Consequently, malicious payloads can be crafted to bypass authentication checks imposed on administrative or sensitive endpoints managed by httpd. Because the httpd service listens on network ports exposed to remote users, an attacker situated on the WAN or LAN can initiate the attack remotely.\nThe step-by-step attack flow involves the remote attacker sending a specially crafted HTTP request targeting the web server interface of the Tenda AC10. When httpd invokes the R7WebsSecurityHandler function to process the request, the flawed logic incorrectly evaluates the authentication state or omits necessary security checks entirely. As a result, the application treats the unauthenticated or improperly authenticated request as valid, granting unauthorized access to restricted resources or sensitive backend handlers.\nThe network exposure of the httpd service combined with the lack of robust authentication checks enables unauthenticated remote code execution or unauthorized configuration access depending on the exact execution context of R7WebsSecurityHandler. No privileges are required by the attacker to initiate the request, lowering the attack barrier significantly. Post-exploitation impact includes full compromise of the affected routing device, interception of local network traffic, or further pivoting into internal network segments connected to the Tenda AC10."
}
CVE-2026-19924: Tenda AC10 Improper Authentication Vulnerability (CRITICAL Severity, CVSS: 9.8) - Sceawere