📦 Ac10u Firmware

by Tenda

🔍 What is Ac10u Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-15218

HIGH CVSS 8.8 Dec 30, 2025

This vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code via a buffer overflow in the lanMask parameter of the /goform/AdvSetLanip endpoint. Attackers can exploit th...

CVE-2025-15215

HIGH CVSS 8.8 Dec 30, 2025

A buffer overflow vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /goform/setPptpUserList endpoint. This a...

CVE-2024-2763

HIGH CVSS 8.8 Mar 21, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code by manipulating the funcpara1 parameter in the formSetCfm function. This a...

CVE-2024-2710

HIGH CVSS 8.8 Mar 20, 2024

This critical vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the setSchedWifi function. Attackers can exploit this without ...

CVE-2024-2708

HIGH CVSS 8.8 Mar 20, 2024

This critical vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formexeCommand function. Attackers can exploit this withou...

CVE-2024-2705

HIGH CVSS 8.8 Mar 20, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code by manipulating the 'list' argument in the formSetQosBand function. This a...

CVE-2024-2703

HIGH CVSS 8.8 Mar 20, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code by manipulating the 'mac' parameter in the formSetDeviceName function. Thi...

CVE-2024-10280

MEDIUM CVSS 6.5 Oct 23, 2024

A null pointer dereference vulnerability in Tenda routers allows remote attackers to cause denial of service by manipulating the Content-Length argument in the websReadEvent function. This affects mul...