HIGH

CVE-2026-16248

Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow

CVSS v3

8.8

HIGH

EPSS Score

exploit probability

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.

Technical details

CVSS v3 Vector
3.1
Published
7/20/2026
Last Modified
7/20/2026

Frequently asked questions

What is CVE-2026-16248?

A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.

Is CVE-2026-16248 actively exploited?

A proof-of-concept exploit exists for CVE-2026-16248, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2026-16248?

CVE-2026-16248 has a CVSS v3 base score of 8.8 (HIGH severity), with vector string 3.1.

Is CVE-2026-16248 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.