{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/ac10-16.03.10.09_multi_tde01/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-16248"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AC10 16.03.10.09_multi_TDE01"],"_cs_severities":["high"],"_cs_tags":["buffer-overflow","rce","firmware","router","web-vulnerability","cve"],"_cs_type":"advisory","_cs_vendors":["Tenda"],"content_html":"\u003cp\u003eA critical stack-based buffer overflow vulnerability, identified as CVE-2026-16248, affects the Tenda AC10 router firmware version 16.03.10.09_multi_TDE01. This flaw is located within the \u003ccode\u003efromAdvSetLanip\u003c/code\u003e function of the \u003ccode\u003e/goform/AdvSetLanip\u003c/code\u003e file, part of the \u003ccode\u003ehttpd/netctrl\u003c/code\u003e component. Attackers can remotely exploit this vulnerability by manipulating the \u003ccode\u003eGetValue/SetValue\u003c/code\u003e arguments, which can lead to arbitrary code execution and full control over the device. The exploit code for this vulnerability has been publicly released, increasing the risk of widespread exploitation. This poses a significant threat to organizations and individuals using the affected Tenda AC10 routers, as compromised devices can be used for unauthorized network access, data exfiltration, or further attacks on internal systems.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a vulnerable Tenda AC10 router exposed to the internet.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a specially designed HTTP request targeting the \u003ccode\u003e/goform/AdvSetLanip\u003c/code\u003e endpoint on the router's web interface.\u003c/li\u003e\n\u003cli\u003eThe malicious HTTP request includes crafted \u003ccode\u003eGetValue\u003c/code\u003e or \u003ccode\u003eSetValue\u003c/code\u003e arguments designed to exceed the buffer limits.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003efromAdvSetLanip\u003c/code\u003e function processes the malformed arguments, leading to a stack-based buffer overflow.\u003c/li\u003e\n\u003cli\u003eThe buffer overflow overwrites critical memory regions, allowing the attacker to inject and execute arbitrary code on the router.\u003c/li\u003e\n\u003cli\u003eUpon successful code execution, the attacker gains full control over the Tenda AC10 router.\u003c/li\u003e\n\u003cli\u003eThe compromised router can then be used as a pivot point for further attacks on the internal network, to monitor or intercept traffic, or to alter device configurations.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-16248 grants attackers complete control over the affected Tenda AC10 router. This can lead to severe consequences including, but not limited to, unauthorized access to the network connected to the router, interception or manipulation of network traffic, and potential for data exfiltration. Attackers could also reconfigure the router to redirect users to malicious websites, launch denial-of-service attacks, or establish persistent backdoors. The public availability of exploit code significantly increases the likelihood of widespread attacks against unpatched devices, posing a critical risk to any organizations or home users utilizing this specific router model.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update Tenda AC10 router firmware to the latest secure version once released by the vendor to patch CVE-2026-16248.\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for the \u003ccode\u003e/goform/AdvSetLanip\u003c/code\u003e endpoint for unusually long or malformed \u003ccode\u003eGetValue\u003c/code\u003e or \u003ccode\u003eSetValue\u003c/code\u003e parameters as described in the \u003ccode\u003eOverview\u003c/code\u003e section.\u003c/li\u003e\n\u003cli\u003eReview network firewall rules to restrict access to router administration interfaces from untrusted external networks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T13:29:45Z","date_published":"2026-07-20T13:29:45Z","id":"https://feed.craftedsignal.io/briefs/2026-07-tenda-ac10-buffer-overflow/","summary":"A stack-based buffer overflow vulnerability (CVE-2026-16248) has been identified in Tenda AC10 firmware version 16.03.10.09_multi_TDE01, residing in the fromAdvSetLanip function of the /goform/AdvSetLanip file within the httpd/netctrl component, which can be remotely exploited by manipulating the GetValue/SetValue argument, with a public exploit now available.","title":"Tenda AC10 Buffer Overflow Vulnerability (CVE-2026-16248)","url":"https://feed.craftedsignal.io/briefs/2026-07-tenda-ac10-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - AC10 16.03.10.09_multi_TDE01","version":"https://jsonfeed.org/version/1.1"}