Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow
CVSS v3
8.8
HIGH
EPSS Score
—
exploit probability
CISA KEV
No
known exploited
Exploitation
poc
SSVC status
A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.
A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.
A proof-of-concept exploit exists for CVE-2026-16248, but active exploitation has not been confirmed at this time.
CVE-2026-16248 has a CVSS v3 base score of 8.8 (HIGH severity), with vector string 3.1.
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.