


Perceptive Security
SOC/SIEM Consultancy

A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability affects the function cgiSysTimeInfoSet of the file /bin/httpd. The manipulation of…
Published:
30 May 2026 at 22:00:00
Alert date:
31 May 2026 at 17:00:50
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A critical stack-based buffer overflow vulnerability has been discovered in Tenda W12 router version 3.0.0.7(4763). The vulnerability affects the cgiSysTimeInfoSet function in the /bin/httpd file, where manipulation of the 'sec' argument can trigger the overflow. This vulnerability can be exploited remotely and poses significant security risks. Public exploits have been disclosed and are available for use, making this a high-priority security issue. The vulnerability allows attackers to potentially execute arbitrary code or cause denial of service on affected devices.
Technical details
Mitigation steps:
Affected products:
Tenda W12
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10189
http://cdn2.v50to.cc/cgiSysTimeInfoSet_overflow.zip
https://vuldb.com/cve/CVE-2026-10189
https://vuldb.com/submit/820021
https://vuldb.com/vuln/367470
https://vuldb.com/vuln/367470/cti
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
