GHSA-f73c-56vj-cw8pHighCVSS 8.8
A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-16248
- https://github.com/teiwiet/tenda-ac10-vulnerabilities/blob/main/advisory-fromAdvSetLanip.md
- https://vuldb.com/cve/CVE-2026-16248
- https://vuldb.com/submit/858411
- https://vuldb.com/vuln/380539
- https://vuldb.com/vuln/380539/cti
- https://www.tenda.com.cn
- https://github.com/advisories/GHSA-f73c-56vj-cw8p