Executive brief
A security vulnerability exists in the Tenda W12 wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending specially crafted data to the router's management interface. This could lead to a complete loss of internet service or unauthorized access to the network's traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda W12 router, specifically within the 'cgiSysTimeInfoSet' function of the '/bin/httpd' binary. The flaw is triggered by improper validation of the 'sec' argument, allowing an attacker to overwrite the stack. This attack can be initiated remotely over the network, though it requires low-level authentication (PR:L). Successful exploitation can lead to arbitrary code execution or a complete system crash (DoS). Public exploit code has been disclosed, increasing the risk of active exploitation.
Affected products
- Tenda W12 3.0.0.7(4763)
Timeline
- 2026-05-31: disclosed: Vulnerability disclosed and CVE published.