CVE-2026-19924: Tenda AC10 httpd R7WebsSecurityHandler improper authentication
A security vulnerability has been detected in Tenda AC10 16.03.10.09multiTDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19924?
CVE-2026-19924 has a severity score of 9.8, classified as critical.
How do I fix CVE-2026-19924?
To fix CVE-2026-19924, update the Tenda AC10 firmware to the latest version provided by Tenda.
What impact does CVE-2026-19924 have on my system?
CVE-2026-19924 can lead to improper authentication, potentially allowing unauthorized remote access to the affected device.
Is CVE-2026-19924 actively being exploited?
There have been reports of CVE-2026-19924 being publicly disclosed, which raises concerns about potential active exploitation.
Which devices are affected by CVE-2026-19924?
CVE-2026-19924 affects the Tenda AC10 model with firmware version 16.03.10.09_multi_TDE01.