Junglewise Threat Intelligence

CVE-2026-10188: Tenda W12 stack buffer overflow in cgistaKickOff

CVE-2026-10188 · Severity: high · CVSS 8.8 · Published 2026-05-31

Technologies: Tenda W12. Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda W12 wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted request. This could lead to a complete loss of internet service or unauthorized access to the network traffic passing through the router.

Technical details

A stack-based buffer overflow vulnerability (CWE-121) exists in the Tenda W12 router firmware version 3.0.0.7(4763). The flaw is located in the 'cgistaKickOff' function within the '/bin/httpd' binary. The vulnerability is triggered by insufficient validation of the 'staMac' parameter, allowing an attacker to overwrite the stack. While the attack requires low-level authentication (PR:L), it can be executed remotely over the network. Successful exploitation can lead to remote code execution (RCE) or a denial-of-service (DoS) condition. Public exploit code has reportedly been released.

Affected products

  • Tenda W12 3.0.0.7(4763)

Timeline

  • 2026-05-31: disclosed
  • 2026-05-31: advisory

References

Related threats