CVE-2026-5549: Tenda AC10 RSA 2048-bit Private Key privkeySrv.pem hard-coded key
A vulnerability was determined in Tenda AC10 16.03.10.10multiTDE01. Affected by this issue is some unknown functionality of the file /webrootro/pem/privkeySrv.pem of the component RSA 2048-bit Private Key Handler. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5549?
CVE-2026-5549 is considered a high-severity vulnerability due to the presence of a hard-coded RSA 2048-bit private key.
How do I fix CVE-2026-5549?
To fix CVE-2026-5549, you should update the Tenda AC10 firmware to the latest version provided by the vendor that addresses this vulnerability.
What components are affected by CVE-2026-5549?
CVE-2026-5549 affects the RSA 2048-bit Private Key Handler within the /webroot_ro/pem/privkeySrv.pem file of Tenda AC10 devices.
What are the potential risks of CVE-2026-5549?
The vulnerability may allow unauthorized access to encrypted communications, compromising device security and user data.
Is there an exploit available for CVE-2026-5549?
While specific exploit details are not disclosed, the nature of this vulnerability suggests that attackers could potentially exploit it for malicious purposes.