CVE-2026-4565 is a high-severity buffer overflow vulnerability affecting Tenda AC21 firmware version 16.03.08.16. This flaw, residing in the formSetQosBand function, allows a remote attacker with low privileges to achieve high confidentiality, integrity, and availability impact by manipulating an argument. With a CVSS score of 8.8, a public exploit is available, significantly increasing the risk of full device compromise. Although not currently in CISA KEV, its public exploit and community discussion warrant immediate mitigation actions, such as disabling WAN administration.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.03.08.16CPE matchmatch criteria | cpe:2.3:o:tenda:ac21_firmware:16.03.08.16:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.