← Back
IoT / Embedded
CVE-2026-5550 high CVSS 8.8

A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The...

Summary

A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected.

AI summary openai / gpt-4o

Tenda AC10 16.03.10.10_multi_TDE01で、/bin/httpdのfromSysToolChangePwd関数においてスタックベースのバッファオーバーフローが発生する脆弱性が特定されました。この脆弱性はリモートから攻撃を開始することが可能で、複数のエンドポイントに影響を与える可能性があります。
❓ What is the problem
Tenda AC10におけるスタックベースのバッファオーバーフローの脆弱性。
📍 Affected scope
/bin/httpdのfromSysToolChangePwd関数
🔥 Severity
リモート攻撃が可能で、複数のエンドポイントに影響する可能性があるため重要。
🔧 How to fix
ファームウェアのアップデートをTendaから提供され次第、適用してください。
🛡️ Workaround
現在パッチが提供されていない場合、ネットワークアクセス制御リストを使用して影響を受けるエンドポイントへの不要なアクセスを制限する。
🔍 Detection
脆弱性に関する侵入試行がないか、サーバログやネットワーク検査を通じて確認する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →