


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in Tenda W12 3.0.0.7(4763). This affects the function cgistaKickOff of the file /bin/httpd. Executing a manipulation of the argument staMa…
Published:
30 May 2026 at 22:00:00
Alert date:
31 May 2026 at 16:00:53
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A critical stack-based buffer overflow vulnerability has been discovered in Tenda W12 router firmware version 3.0.0.7(4763). The flaw exists in the cgistaKickOff function within the /bin/httpd file, where manipulation of the staMac argument can trigger the overflow. This vulnerability can be exploited remotely by attackers. A public exploit has been released and is available for use, significantly increasing the risk to affected devices. The vulnerability allows remote code execution on vulnerable Tenda W12 routers.
Technical details
Mitigation steps:
Affected products:
Tenda W12
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10188
http://cdn2.v50to.cc/Tenda%20W12%20cgistaKickOff%20overflow.zip
https://vuldb.com/cve/CVE-2026-10188
https://vuldb.com/submit/820018
https://vuldb.com/vuln/367469
https://vuldb.com/vuln/367469/cti
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
