


Perceptive Security
SOC/SIEM Consultancy

A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability affects the function cgiSysTimeInfoSet of the file /bin/httpd. The manipulation of…
Published:
30 mei 2026 om 22:00:00
Alert date:
31 mei 2026 om 17:00:50
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A critical stack-based buffer overflow vulnerability has been discovered in Tenda W12 router version 3.0.0.7(4763). The vulnerability affects the cgiSysTimeInfoSet function in the /bin/httpd file, where manipulation of the 'sec' argument can trigger the overflow. This vulnerability can be exploited remotely and poses significant security risks. Public exploits have been disclosed and are available for use, making this a high-priority security issue. The vulnerability allows attackers to potentially execute arbitrary code or cause denial of service on affected devices.
Technical details
Mitigation steps:
Affected products:
Tenda W12
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10189
http://cdn2.v50to.cc/cgiSysTimeInfoSet_overflow.zip
https://vuldb.com/cve/CVE-2026-10189
https://vuldb.com/submit/820021
https://vuldb.com/vuln/367470
https://vuldb.com/vuln/367470/cti
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
