CVE-2026-11528
Tenda AC18
A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. The manipulation of the argument callback results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
- CVSS
- 7.4
- EPSS
- 0.47% 38.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.09