VYPR
Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 20, 2026

Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow

CVE-2026-16248

Description

A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.

Affected products

2
  • Tenda/Ac10inferred2 versions
    =16.03.10.09_multi_TDE01+ 1 more
    • (no CPE)range: =16.03.10.09_multi_TDE01
    • (no CPE)range: 16.03.10.09_multi_TDE01

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.