<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-19924 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-19924/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 16 Aug 2026 02:22:36 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-19924/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in Tenda AC10 Router</title><link>https://feed.craftedsignal.io/briefs/2026-08-tenda-ac10-auth-bypass/</link><pubDate>Sun, 16 Aug 2026 02:22:36 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-tenda-ac10-auth-bypass/</guid><description>An improper authentication vulnerability in the Tenda AC10 router's httpd component allows remote, unauthenticated attackers to gain unauthorized access to the device.</description><content:encoded><![CDATA[<p>A critical security vulnerability (CVE-2026-19924) has been identified in Tenda AC10 routers running firmware version 16.03.10.09_multi_TDE01. The flaw exists within the <code>R7WebsSecurityHandler</code> function of the <code>httpd</code> daemon. This vulnerability allows remote, unauthenticated attackers to bypass authentication mechanisms, granting them unauthorized access to the router's management interface or sensitive device settings. Publicly disclosed exploit code for this vulnerability is currently available, significantly lowering the barrier for exploitation. Given the network-facing nature of the affected service, this flaw poses a severe risk to device integrity and internal network visibility.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify Tenda AC10 devices reachable via the public internet.</li>
<li>Attacker initiates an HTTP connection to the target device's management web interface on port 80 or 443.</li>
<li>Attacker sends a crafted HTTP request designed to interact with the vulnerable <code>R7WebsSecurityHandler</code> function.</li>
<li>The <code>httpd</code> component fails to properly validate the authentication state during this request.</li>
<li>The vulnerability is triggered, allowing the attacker to bypass the standard login process.</li>
<li>Attacker gains session-level or administrative access to the device management panel.</li>
<li>Attacker performs unauthorized configuration changes, such as modifying DNS settings, exfiltrating credentials, or pivoting into the local network.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for full administrative control over the affected Tenda AC10 routers. Potential consequences include device hijacking, interception of network traffic, modification of DNS settings to facilitate man-in-the-middle (MitM) attacks, and unauthorized access to devices on the internal network. The vulnerability impacts residential and small-business environments where these routers are deployed.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security operations and IT teams:</p>
<ul>
<li>Immediately restrict access to the Tenda AC10 management interface to internal or VPN-only networks.</li>
<li>Check for and apply the latest firmware updates from Tenda to address CVE-2026-19924.</li>
<li>Monitor logs for unusual HTTP traffic patterns originating from external IP addresses directed at the router's management interface.</li>
<li>Audit network perimeter configurations to ensure management ports for networking hardware are not exposed to the public internet.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>authentication-bypass</category><category>cve-2026-19924</category></item></channel></rss>