CVE-2026-5548Disclosure(tenda / ac10)

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac10
  • ac10_firmware

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
ac10ac10_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-05: 3Technical Details · 2026-04-05: 204-05
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5548 A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing … https://www.cve.org/CVERecord?id=CVE-2026-5548

    Post summary

    The post announces the discovery of CVE‑2026‑5548 in a Tenda AC10 device, describing the affected function in httpd, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    00010314
    56.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5548 A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing … https://www.cve.org/CVERecord?id=CVE-2026-5548 ----- Traducción: CVE-2026-5548 Se … http://infoflow.cloud`

    Post summary

    CVE-2026-5548 has been disclosed for Tenda AC10 firmware, targeting the fromSysToolChangePwd function in /bin/httpd, with no current evidence of exploitation, patches, or detailed technical data.

    0000042
    63 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5548: HIGH] Cybersecurity alert: Vulnerability discovered in Tenda AC10 16.03.10.10_multi_TDE01 allows remote attackers to trigger a stack-based buffer overflow via a manipulated argument.#cve,CVE-2026-5548,#cybersecurity https://cvefind.com/CVE-2026-5548

    Post summary

    The post discloses CVE-2026-5548, a stack-based buffer overflow in Tenda AC10 firmware that allows remote attackers to trigger a crash, but it provides no proof of concept, exploit code, patch information, or evidence of active exploitation.

    0000041
    612 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac104.0--
OStendaac10_firmware16.03.10.10_multi_tde01--

Explore more