logo

CVE-2026-51380: Tenda AC10 v3 Buffer Overflow Enables DoS and Remote Code Execution

ID: 6d5d18fc-878c-5b99-a48a-09195be47bf9

STIX ID: report--6d5d18fc-878c-5b99-a48a-09195be47bf9

Feed Name: CosmicBytez Labs

Threat Score
72/100

Date Published: 2026-07-16

Date Updated: 2026-07-17

...
...

**Executive Summary:** A critical (CVSS 9.8) unauthenticated stack buffer overflow in the Tenda AC10 v3 (/cgi-bin/UploadCfg, CVE-2026-51380) allows remote attackers to cause a permanent DoS or achieve remote code execution on firmware V03.03.16.09; no official patch is available and mitigations include disabling remote management and UPnP, restricting LAN access, or replacing the device.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.