Executive brief
A security vulnerability has been identified in the Tenda W12 wireless router. This flaw exists in the device's web management interface and could allow an attacker to disrupt the router's operations or potentially take control of the device. Successful exploitation could lead to a complete loss of service or unauthorized access to the network traffic passing through the router.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in the Tenda W12 router, specifically within the 'set_local_time_0' function of the '/bin/httpd' binary. The flaw is triggered by improper validation of the 'Time' argument, allowing an attacker to overwrite memory on the stack. This attack can be launched remotely over the network, though it requires low-level authentication (PR:L). Successful exploitation can lead to remote code execution (RCE) or a crash of the HTTP service (DoS). A public exploit is reportedly available.
Affected products
- Tenda W12 3.0.0.7(4763)
Timeline
- 2026-05-31: disclosed: Vulnerability published via VulDB and NVD.