Executive brief
A security vulnerability exists in the Tenda CX12L router's Wi-Fi scheduling feature. An attacker can exploit this flaw to crash the router's management interface or potentially take control of the device. This could lead to a complete loss of internet connectivity for the network or unauthorized access to the router's settings.
Technical details
A stack-based buffer overflow exists in the 'setSchedWifi' function within the '/goform/openSchedWifi' endpoint of Tenda CX12L firmware version 16.03.53.12. The vulnerability is caused by the use of the unsafe 'strcpy' function to copy user-supplied 'schedStartTime' and 'schedEndTime' parameters into a fixed-size 25-byte heap-allocated buffer without length validation. A remote attacker with low privileges can provide oversized strings to trigger the overflow, leading to memory corruption, a crash of the 'httpd' process (DoS), or potential arbitrary code execution. A public exploit (PoC) has been released.
Affected products
- Tenda CX12L Router Firmware 16.03.53.12
Timeline
- 2026-05-22: disclosed: Vulnerability details and PoC shared on GitHub.
- 2026-06-08: advisory: CVE-2026-11504 published in NVD.