LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-4565 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: March 23, 2026

Tenda AC21 - Buffer Overflow

Published: March 23, 2026Updated: March 23, 2026Remote Exploitable

Overview

Tenda AC21 16.03.08.16 contains a buffer overflow caused by manipulation of the argument list in formSetQosBand function in /goform/SetNetControlList, letting remote attackers cause memory corruption, exploit requires no special privileges.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Remote attackers can cause memory corruption leading to potential code execution or system crash.

Mitigation

Update to the latest version.

Social Media Activity(4 posts)

Offensive Sequence
Offensive Sequence
@offseq
Mar 23, 2026

🚨 HIGH: CVE-2026-4565 — Tenda AC21 (16.03.08.16) has a remote buffer overflow in /goform/SetNetControlList. Public exploit out; full device compromise possible. Disable WAN admin, monitor, and segment networks ASAP. https://radar.offseq.com/threat/cve-2026-4565-buffer-overflow-in-tenda-ac21-5d23ce15 #OffSeq #Vulnerability #NetSec #Router

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 23, 2026

🟠 CVE-2026-4565 - High (8.8) A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function formSetQosBand of the file /goform/SetNetControlList. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely.... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-4565/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
Offensive Sequence
Offensive Sequence
@offseq
Mar 23, 2026

🚨 HIGH: CVE-2026-4565 — Tenda AC21 (16.03.08.16) has a remote buffer overflow in /goform/SetNetControlList. Public exploit out; full device compromise possible. Disable WAN admin, monitor, and segment networks ASAP. https://radar.offseq.com/threat/cve-2026-4565-buffer-overflow-in-tenda-ac21-5d23ce15 #OffSeq #Vulnerability #NetSec #Router

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 23, 2026

🟠 CVE-2026-4565 - High (8.8) A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function formSetQosBand of the file /goform/SetNetControlList. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely.... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-4565/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-4565
Severity
High
CVSS Score
8.8
Type
buffer_overflow
Status
new
EPSS
0.0%
Social Posts
4

CWE

  • CWE-119

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days