Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 20, 2026
Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow
CVE-2026-16248
Description
A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/teiwiet/tenda-ac10-vulnerabilities/blob/main/advisory-fromAdvSetLanip.mdmitreexploit
- vuldb.com/cve/CVE-2026-16248mitrethird-party-advisory
- vuldb.com/submit/858411mitrethird-party-advisory
- vuldb.com/vuln/380539mitrevdb-entrytechnical-description
- vuldb.com/vuln/380539/ctimitresignaturepermissions-required
- www.tenda.com.cnmitreproduct
News mentions
0No linked articles in our index yet.