Junglewise Threat Intelligence

CVE-2026-10191: Tenda W12 stack overflow in cgiWifiMacFilterSet

CVE-2026-10191 · Severity: high · CVSS 8.8 · Published 2026-05-31

Technologies: Tenda W12. Vendors: Tenda.

Executive brief

A security vulnerability exists in the Tenda W12 wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can exploit this flaw to gain unauthorized control over the device by sending specially crafted data to the router's management interface. This could lead to a complete disruption of internet services, interception of network traffic, or unauthorized access to the internal network.

Technical details

A stack-based buffer overflow vulnerability (CWE-121) exists in the Tenda W12 router firmware version 3.0.0.7(4763). The flaw is located within the 'cgiWifiMacFilterSet' function of the '/bin/httpd' binary. It is triggered by improper length validation of the 'wifiMacFilterSet.macList.mac' argument. A remote attacker with low-level privileges can exploit this by sending a malicious request to the web management interface, potentially leading to remote code execution (RCE) or a crash of the HTTP service. Public exploit details have been disclosed.

Affected products

  • Tenda W12 3.0.0.7(4763)

Timeline

  • 2026-05-31: disclosed
  • 2026-05-31: advisory

References

Related threats