Executive brief
A vulnerability exists in the Tenda W12 router's web management interface. An attacker can remotely trigger a denial-of-service condition, making the router's management console or networking services unavailable. This could disrupt business operations and prevent administrators from managing the network device.
Technical details
A denial of service (DoS) vulnerability exists in the Tenda W12 router, specifically within the 'cgiSysWebTimeoutSet' function of the '/bin/httpd' binary. The vulnerability is triggered by manipulating the 'web_over_time' argument within the Web Management Interface. An attacker with low-level privileges can exploit this over the network to cause an improper resource shutdown or release (CWE-404), leading to a denial of service. Public exploit code is reportedly available.
Affected products
- Tenda W12 3.0.0.7(4763)
Timeline
- 2026-05-31: advisory: NVD publication date