Junglewise Threat Intelligence

CVE-2026-10190: Tenda W12 denial of service in Web Management Interface

CVE-2026-10190 · Severity: medium · CVSS 6.5 · Published 2026-05-31

Technologies: Tenda W12. Vendors: Tenda.

Executive brief

A vulnerability exists in the Tenda W12 router's web management interface. An attacker can remotely trigger a denial-of-service condition, making the router's management console or networking services unavailable. This could disrupt business operations and prevent administrators from managing the network device.

Technical details

A denial of service (DoS) vulnerability exists in the Tenda W12 router, specifically within the 'cgiSysWebTimeoutSet' function of the '/bin/httpd' binary. The vulnerability is triggered by manipulating the 'web_over_time' argument within the Web Management Interface. An attacker with low-level privileges can exploit this over the network to cause an improper resource shutdown or release (CWE-404), leading to a denial of service. Public exploit code is reportedly available.

Affected products

  • Tenda W12 3.0.0.7(4763)

Timeline

  • 2026-05-31: advisory: NVD publication date

References

Related threats