📦 Ac10 Firmware

by Tenda

🔍 What is Ac10 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-67073

CRITICAL CVSS 9.8 Dec 17, 2025

A buffer overflow vulnerability in Tenda AC10V4.0 routers allows remote attackers to cause denial of service or potentially execute arbitrary code by sending a specially crafted POST request to the /g...

CVE-2025-45779

CRITICAL CVSS 9.8 May 12, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers via a buffer overflow in the formSetPPTPUserList handler. Attackers can exploit this by sending specially cra...

CVE-2025-25456

CRITICAL CVSS 9.8 Apr 15, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers via a buffer overflow in the AdvSetMacMtuWan function. Attackers can exploit this by sending specially crafte...

CVE-2025-25675

CRITICAL CVSS 9.8 Feb 20, 2025

This CVE describes a command injection vulnerability in Tenda AC10 routers that allows remote attackers to execute arbitrary commands with root privileges. Attackers can exploit this by sending specia...

CVE-2023-45480

CRITICAL CVSS 9.8 Nov 29, 2023

CVE-2023-45480 is a critical stack-based buffer overflow vulnerability in Tenda AC10 routers. Attackers can exploit this by sending specially crafted requests to the 'src' parameter, potentially allow...

CVE-2023-45482

CRITICAL CVSS 9.8 Nov 29, 2023

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers via a stack overflow in the get_parentControl_list_Info function. Attackers can exploit this by sending speci...

CVE-2023-45484

CRITICAL CVSS 9.8 Nov 29, 2023

This vulnerability is a stack overflow in Tenda AC10 routers via the shareSpeed parameter in the fromSetWifiGuestBasic function. It allows remote attackers to execute arbitrary code or cause denial of...

CVE-2023-42320

CRITICAL CVSS 9.8 Sep 18, 2023

A buffer overflow vulnerability in Tenda AC10V4 routers allows remote attackers to cause denial of service by sending specially crafted requests to the GetParentControlInfo function. This affects Tend...

CVE-2023-38936

CRITICAL CVSS 9.8 Aug 7, 2023

This CVE describes a stack overflow vulnerability in multiple Tenda router models via the speed_dir parameter in the formSetSpeedWan function. Attackers can exploit this to execute arbitrary code or c...

CVE-2023-37717

CRITICAL CVSS 9.8 Jul 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the fromDhcpListClient function. Attackers can exploit this by sending specially ...

CVE-2023-37711

CRITICAL CVSS 9.8 Jul 10, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the deviceId parameter. Attackers can gain full control of the device without aut...

CVE-2023-34566

CRITICAL CVSS 9.8 Jun 8, 2023

This vulnerability is a stack overflow in Tenda AC10 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the /goform/saveParentControlInfo endpoint....

CVE-2023-27013

CRITICAL CVSS 9.8 Apr 7, 2023

This vulnerability in Tenda AC10 routers allows attackers to trigger a stack overflow via the get_parentControl_list_Info function. Attackers can cause Denial of Service or execute arbitrary code by s...

CVE-2023-27015

CRITICAL CVSS 9.8 Apr 7, 2023

This vulnerability in Tenda AC10 routers allows attackers to cause denial of service or execute arbitrary code by exploiting a stack overflow in the sub_4A75C0 function. Attackers can achieve this by ...

CVE-2023-27017

CRITICAL CVSS 9.8 Apr 7, 2023

CVE-2023-27017 is a critical stack overflow vulnerability in Tenda AC10 routers that allows attackers to cause denial of service or execute arbitrary code via crafted network requests. This affects us...

CVE-2023-27019

CRITICAL CVSS 9.8 Apr 7, 2023

This CVE describes a critical stack overflow vulnerability in Tenda AC10 routers that allows attackers to execute arbitrary code or cause denial of service. Attackers can exploit this by sending speci...

CVE-2023-27021

CRITICAL CVSS 9.8 Apr 7, 2023

This vulnerability in Tenda AC10 routers allows attackers to cause denial of service or execute arbitrary code by exploiting a stack overflow in the firewall configuration function. It affects Tenda A...

CVE-2022-32054

CRITICAL CVSS 9.8 Jul 7, 2022

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers by exploiting improper input validation in the lanIp parameter. Attackers can gain full control of affected d...

CVE-2025-12622

HIGH CVSS 8.8 Nov 3, 2025

A buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code by manipulating the 'getui' parameter in the formSysRunCmd function. This affects Tenda AC10 rou...

CVE-2025-57215

HIGH CVSS 7.5 Aug 28, 2025

A stack-based buffer overflow vulnerability exists in Tenda AC10 routers running firmware v16.03.10.20. Attackers can exploit this via the get_parentControl_list_Info function to potentially execute a...

CVE-2025-5629

HIGH CVSS 8.8 Jun 5, 2025

A critical buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP requests to the formSetPPTPServer function. This affe...

CVE-2025-25454

HIGH CVSS 7.5 Apr 17, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers via a buffer overflow in the AdvSetMacMtuWan function. Attackers can exploit this by sending specially crafte...

CVE-2025-25457

HIGH CVSS 7.5 Apr 17, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers via a buffer overflow in the AdvSetMacMtuWan function. Attackers can exploit this by sending specially crafte...

CVE-2025-3161

HIGH CVSS 8.8 Apr 3, 2025

A critical stack-based buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code by manipulating the 'list' parameter in the ShutdownSetAdd function. This a...

CVE-2025-0528

HIGH CVSS 7.2 Jan 17, 2025

This critical vulnerability in Tenda AC8, AC10, and AC18 routers allows remote attackers to execute arbitrary commands via command injection in the HTTP request handler for the /goform/telnet endpoint...

CVE-2024-11248

HIGH CVSS 8.8 Nov 15, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code by manipulating the rebootTime parameter. This affects Tenda AC10 routers r...

CVE-2024-11061

HIGH CVSS 8.8 Nov 11, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code by manipulating the timeZone parameter. This affects Tenda AC10 routers run...

CVE-2024-11056

HIGH CVSS 8.8 Nov 10, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code by manipulating the wpapsk_crypto parameter. This affects Tenda AC10 router...

CVE-2024-33365

HIGH CVSS 7.5 Jul 29, 2024

A buffer overflow vulnerability in Tenda AC10 routers allows remote attackers to execute arbitrary code via the Virtual_Data_Check function in the httpd component. This affects Tenda AC10 v4 routers r...

CVE-2024-32317

HIGH CVSS 7.5 Apr 17, 2024

This CVE describes a stack overflow vulnerability in Tenda AC10 routers that allows attackers to execute arbitrary code by sending specially crafted requests to the adslPwd parameter. The vulnerabilit...

CVE-2025-67074

MEDIUM CVSS 6.5 Dec 17, 2025

A buffer overflow vulnerability in Tenda AC10V4.0 routers allows remote attackers to cause denial of service or potentially execute arbitrary code by sending a specially crafted POST request to the /g...

CVE-2025-57220

MEDIUM CVSS 5.3 Aug 28, 2025

An input validation flaw in the 'ate' service of Tenda AC10 routers allows unauthenticated attackers to send crafted UDP packets to escalate privileges to root. This affects Tenda AC10 v4.0 devices ru...

CVE-2025-57217

MEDIUM CVSS 5.3 Aug 28, 2025

This CVE describes a stack buffer overflow vulnerability in Tenda AC10 routers that allows remote attackers to execute arbitrary code via the Password parameter during login authentication. Attackers ...

CVE-2025-25453

MEDIUM CVSS 4.6 Apr 15, 2025

This vulnerability allows attackers to cause a buffer overflow in Tenda AC10 routers via the AdvSetMacMtuWan function's serviceName2 parameter. Successful exploitation could lead to denial of service ...

CVE-2024-10280

MEDIUM CVSS 6.5 Oct 23, 2024

A null pointer dereference vulnerability in Tenda routers allows remote attackers to cause denial of service by manipulating the Content-Length argument in the websReadEvent function. This affects mul...