CVE-2026-4565
HIGHTenda AC21 SetNetControlList formSetQosBand buffer overflow
Title source: cnaDescription
A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function formSetQosBand of the file /goform/SetNetControlList. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.
References (6)
Scores
CVSS v3
8.8
EPSS
0.0009
EPSS Percentile
24.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-119
CWE-120
Status
published
Products (2)
Tenda/AC21
16.03.08.16
tenda/ac21_firmware
16.03.08.16
Published
Mar 23, 2026
Tracked Since
Mar 23, 2026