What is CVE-2026-19924?
This critical vulnerability in Tenda AC10 routers version 16.03.10.09_multi_TDE01 affects the R7WebsSecurityHandler function in the httpd component, leading to improper authentication. An attacker can exploit this remotely to compromise the device, requiring immediate isolation from the network and deactivation until a vendor patch is released.
Azərbaycanca: Bu kritik zəiflik Tenda AC10 routerlərinin 16.03.10.09_multi_TDE01 versiyasında httpd komponentinin R7WebsSecurityHandler funksiyasında səhv autentifikasiyaya səbəb olur. Təcavüzkar bu boşluqdan istifadə edərək cihazı uzaqdan ələ keçirə bilər, ona görə də cihaz dərhal şəbəkədən təcrid edilməli və istehsalçı tərəfindən yeniləmə təmin olunana qədər deaktiv edilməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which device and version are affected by CVE-2026-19924?
This critical vulnerability affects Tenda AC10 routers version 16.03.10.09_multi_TDE01.
What is the recommended action if CVE-2026-19924 is exploited?
The device should be immediately isolated from the network and deactivated until a vendor patch is released.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.