CVE-2026-16248: Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow
A vulnerability was found in Tenda AC10 16.03.10.09multiTDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16248?
The severity of CVE-2026-16248 is high, rated at 8.8.
How do I fix CVE-2026-16248?
To fix CVE-2026-16248, update the Tenda AC10 firmware to the latest version provided by the vendor.
What component is vulnerable in CVE-2026-16248?
CVE-2026-16248 affects the fromAdvSetLanip function within the httpd/netctrl component.
What type of vulnerability is CVE-2026-16248?
CVE-2026-16248 is classified as a stack-based buffer overflow vulnerability.
Can CVE-2026-16248 be exploited remotely?
Yes, CVE-2026-16248 can be exploited remotely as the attack can be performed from the network.