Tenda AC10 Stack Overflow Vulnerability in get_parentControl_list_Info Function

Vulnerability

A stack overflow vulnerability has been identified in the Tenda AC10 router running firmware v4.0 v16.03.10.20. The issue arises in the function get_parentControl_list_Info, where a heap-based buffer overflow can be exploited via the deviceId parameter.

Impact

Exploitation of this vulnerability leads to a heap-based buffer overflow, which can commonly result in arbitrary code execution or causing a denial-of-service condition.

Added: Aug 28, 2025, 7:24 PM
Updated: Aug 28, 2025, 9:19 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
7.8
remediation
0.0
relevance
0.4
threat
0.0
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.