CVE-2026-5548: Tenda AC10 httpd fromSysToolChangePwd stack-based overflow
A vulnerability was found in Tenda AC10 16.03.10.10multiTDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5548?
CVE-2026-5548 is classified as a high-severity vulnerability due to the potential for stack-based buffer overflow.
How do I fix CVE-2026-5548?
To mitigate CVE-2026-5548, it is recommended to update the Tenda AC10 firmware to a version that addresses this vulnerability.
What systems are affected by CVE-2026-5548?
CVE-2026-5548 affects the Tenda AC10 firmware version 16.03.10.10_multi_TDE01.
What type of vulnerability is CVE-2026-5548?
CVE-2026-5548 is a stack-based buffer overflow vulnerability found in the function fromSysToolChangePwd.
Can CVE-2026-5548 lead to remote code execution?
Yes, CVE-2026-5548 can potentially allow an attacker to execute arbitrary code remotely due to the nature of the buffer overflow.