Another Tenda router flaw scores 9.8 - but check your firmware before panicking
A critical authentication bypass has been logged against a single Tenda AC10 firmware build - here's what's actually confirmed and what's still guesswork.
A newly published vulnerability tracked as CVE-2026-19924 has landed a critical CVSS score of 9.8, the kind of number that tends to make headlines on its own. The catch, as ever, is knowing exactly what’s affected and what isn’t - and this one is narrower than the score alone suggests.
What the bug actually does
According to the NVD listing, the flaw sits in a specific firmware build of the Tenda AC10 home router: version 16.03.10.09_multi_TDE01. It affects a function called R7WebsSecurityHandler within the router’s httpd component - the bit of software that serves up its web-based admin interface. The problem is described as “improper authentication”, which in plain terms usually means a way to get past a login screen that shouldn’t let you through.
Crucially, NVD notes the attack “may be initiated remotely” and that “the exploit has been disclosed publicly and may be used” - wording that means proof-of-concept details are out there, not that attacks are confirmed to be happening in the wild right now. Those are different things, and NVD’s record doesn’t claim the latter.
The severity numbers vary depending on which scoring system and source you look at. VulDB, which submitted the assessment, rates it 9.8 (Critical) under CVSS 3.1, but only 8.9 (High) under the newer CVSS 4.0 scale. NIST itself hasn’t yet issued its own NVD assessment for either version, so the “critical” tag currently rests entirely on VulDB’s own scoring rather than an independent government verification.
So who is actually at risk
This is squarely a consumer and small-office router issue, not something that touches enterprise networks, cloud platforms or everyday apps. If you don’t own a Tenda AC10, or you own one running a different firmware version, this specific CVE simply doesn’t apply to you.
For anyone who does have an AC10 on this exact build, the risk is real in principle: an attacker who can reach the router’s web management interface - either because it’s exposed to the internet or because they’re already on your local network - could potentially bypass authentication without needing a password. Since router admin panels typically control DNS settings, port forwarding and Wi-Fi credentials, that’s not a trivial foothold if it can be exploited reliably.
What we don’t know, based on the published record, is how many devices are actually running this exact firmware version, whether Tenda has issued or plans a patch, or whether real-world exploitation attempts have actually begun. Those three unknowns are exactly the ones worth watching before treating this as an active emergency.
What to do about it
Check your Tenda AC10’s firmware version via its admin panel and compare it against 16.03.10.09_multi_TDE01. If you’re unsure, checking for and installing the latest firmware from Tenda’s official support channels is sensible regardless, since router manufacturers routinely patch authentication issues without much fanfare. It’s also worth confirming your router’s admin interface isn’t needlessly exposed to the open internet - a basic hygiene step that neutralises a huge share of “remote” router vulnerabilities regardless of the CVE in question.
None of this warrants panic. It’s a serious flaw on paper, confined to one product and firmware build, with public exploit details but no confirmed mass exploitation. Update if you’re affected, and move on.