AC10
Tenda- Product type
- Operating system
- Catalog vulnerabilities
- 30
Severity across 19 analyzed records
en
Severity across 19 analyzed records
Verify to analyze this security profile
As of 10/06/2026, within CyStack's analyzed data, AC10 has 2 security vulnerabilities published in the last 90 days. Of these, 2 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of AC10 and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-19924Tenda AC10 httpd R7WebsSecurityHandler improper authentication | Exploitation statusPublic exploit | FixNot confirmed | Published08/16/2026 | SeverityCritical |
CVE-2026-16248Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published07/20/2026 | SeverityHigh |
CVE-2026-5550Tenda AC10 httpd fromSysToolChangePwd stack-based overflow | Exploitation statusNot known exploited | FixNot confirmed | Published04/05/2026 | SeverityHigh |
CVE-2026-5549Tenda AC10 RSA 2048-bit Private Key privkeySrv.pem hard-coded key | Exploitation statusPublic exploit | FixNot confirmed | Published04/05/2026 | SeverityMedium |
CVE-2026-5548Tenda AC10 httpd fromSysToolChangePwd stack-based overflow | Exploitation statusNot known exploited | FixNot confirmed | Published04/05/2026 | SeverityHigh |
CVE-2026-5547Tenda AC10 httpd formAddMacfilterRule os command injection | Exploitation statusNot known exploited | FixNot confirmed | Published04/05/2026 | SeverityMedium |
CVE-2025-12622Tenda AC10 SysRunCmd formSysRunCmd buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published11/03/2025 | SeverityHigh |
CVE-2025-9309Tenda AC10 MD5 Hash shadow hard-coded credentials | Exploitation statusPublic exploit | FixNot confirmed | Published08/21/2025 | SeverityLow |
CVE-2025-8178Tenda AC10 RequestsProcessLaid heap-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published07/26/2025 | SeverityHigh |
CVE-2025-5629Tenda AC10 HTTP SetPptpServerCfg formSetPPTPServer buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/05/2025 | SeverityHigh |
CVE-2025-4896Tenda AC10 UserCongratulationsExec buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published05/18/2025 | SeverityHigh |
CVE-2025-3161Tenda AC10 ShutdownSetAdd stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/03/2025 | SeverityHigh |
CVE-2025-0528Tenda AC8/AC10/AC18 HTTP Request telnet command injection | Exploitation statusPublic exploit | FixNot confirmed | Published01/17/2025 | SeverityHigh |
CVE-2024-11248Tenda AC10 SetSysAutoRebbotCfg formSetRebootTimer stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published11/15/2024 | SeverityHigh |
CVE-2024-11061Tenda AC10 fast_setting_wifi_set FUN_0044db3c stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published11/11/2024 | SeverityHigh |
CVE-2024-11056Tenda AC10 WifiExtraSet FUN_0046AC38 stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published11/10/2024 | SeverityHigh |
CVE-2024-10280Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference | Exploitation statusPublic exploit | FixNot confirmed | Published10/23/2024 | SeverityHigh |
CVE-2024-2856Tenda AC10 SetSysTimeCfg fromSetSysTime stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/24/2024 | SeverityHigh |
CVE-2024-2581Tenda AC10 SetStaticRouteCfg fromSetRouteStatic stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/18/2024 | SeverityHigh |
CVE-2023-45481 | Exploitation statusPublic exploit | FixNot confirmed | Published11/29/2023 | SeverityCritical |
CVE-2023-40901 | Exploitation statusNot known exploited | FixNot confirmed | Published08/24/2023 | SeverityUnknown |
CVE-2023-38931 | Exploitation statusPublic exploit | FixNot confirmed | Published08/07/2023 | SeverityUnknown |
CVE-2023-38936 | Exploitation statusPublic exploit | FixNot confirmed | Published08/07/2023 | SeverityUnknown |
CVE-2023-38935 | Exploitation statusPublic exploit | FixNot confirmed | Published08/07/2023 | SeverityUnknown |
CVE-2023-38937 | Exploitation statusPublic exploit | FixNot confirmed | Published08/07/2023 | SeverityUnknown |
CVE-2023-37716 | Exploitation statusPublic exploit | FixNot confirmed | Published07/14/2023 | SeverityUnknown |
CVE-2023-37717 | Exploitation statusPublic exploit | FixNot confirmed | Published07/14/2023 | SeverityUnknown |
CVE-2023-37710 | Exploitation statusPublic exploit | FixNot confirmed | Published07/10/2023 | SeverityUnknown |
CVE-2023-37711 | Exploitation statusPublic exploit | FixNot confirmed | Published07/10/2023 | SeverityUnknown |
CVE-2023-37144 | Exploitation statusPublic exploit | FixNot confirmed | Published07/07/2023 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan