CVE-2026-5550: Tenda AC10 httpd fromSysToolChangePwd stack-based overflow
A vulnerability was identified in Tenda AC10 16.03.10.10multiTDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5550?
CVE-2026-5550 has a high severity rating due to its potential for remote exploitation and stack-based buffer overflow.
How do I fix CVE-2026-5550?
To fix CVE-2026-5550, update the Tenda AC10 firmware to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2026-5550?
CVE-2026-5550 could allow an attacker to execute arbitrary code, leading to a complete compromise of the affected device.
Which devices are affected by CVE-2026-5550?
CVE-2026-5550 specifically affects Tenda AC10 firmware version 16.03.10.10_multi_TDE01.
Is there a way to detect exploitation attempts for CVE-2026-5550?
While direct detection methods may vary, monitoring network traffic for unauthorized access attempts and unusual behavior can help identify potential exploitation of CVE-2026-5550.