{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-19924/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-19924"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AC10 (16.03.10.09_multi_TDE01)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","authentication-bypass","cve-2026-19924"],"_cs_type":"advisory","_cs_vendors":["Tenda"],"content_html":"\u003cp\u003eA critical security vulnerability (CVE-2026-19924) has been identified in Tenda AC10 routers running firmware version 16.03.10.09_multi_TDE01. The flaw exists within the \u003ccode\u003eR7WebsSecurityHandler\u003c/code\u003e function of the \u003ccode\u003ehttpd\u003c/code\u003e daemon. This vulnerability allows remote, unauthenticated attackers to bypass authentication mechanisms, granting them unauthorized access to the router's management interface or sensitive device settings. Publicly disclosed exploit code for this vulnerability is currently available, significantly lowering the barrier for exploitation. Given the network-facing nature of the affected service, this flaw poses a severe risk to device integrity and internal network visibility.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify Tenda AC10 devices reachable via the public internet.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an HTTP connection to the target device's management web interface on port 80 or 443.\u003c/li\u003e\n\u003cli\u003eAttacker sends a crafted HTTP request designed to interact with the vulnerable \u003ccode\u003eR7WebsSecurityHandler\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ehttpd\u003c/code\u003e component fails to properly validate the authentication state during this request.\u003c/li\u003e\n\u003cli\u003eThe vulnerability is triggered, allowing the attacker to bypass the standard login process.\u003c/li\u003e\n\u003cli\u003eAttacker gains session-level or administrative access to the device management panel.\u003c/li\u003e\n\u003cli\u003eAttacker performs unauthorized configuration changes, such as modifying DNS settings, exfiltrating credentials, or pivoting into the local network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full administrative control over the affected Tenda AC10 routers. Potential consequences include device hijacking, interception of network traffic, modification of DNS settings to facilitate man-in-the-middle (MitM) attacks, and unauthorized access to devices on the internal network. The vulnerability impacts residential and small-business environments where these routers are deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security operations and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict access to the Tenda AC10 management interface to internal or VPN-only networks.\u003c/li\u003e\n\u003cli\u003eCheck for and apply the latest firmware updates from Tenda to address CVE-2026-19924.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual HTTP traffic patterns originating from external IP addresses directed at the router's management interface.\u003c/li\u003e\n\u003cli\u003eAudit network perimeter configurations to ensure management ports for networking hardware are not exposed to the public internet.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T02:22:36Z","date_published":"2026-08-16T02:22:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-tenda-ac10-auth-bypass/","summary":"An improper authentication vulnerability in the Tenda AC10 router's httpd component allows remote, unauthenticated attackers to gain unauthorized access to the device.","title":"Authentication Bypass in Tenda AC10 Router","url":"https://feed.craftedsignal.io/briefs/2026-08-tenda-ac10-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-19924","version":"https://jsonfeed.org/version/1.1"}