Junglewise Threat Intelligence

CVE-2026-5609: Tenda i12 stack overflow in formwrlSSIDset

CVE-2026-5609 · Severity: high · CVSS 8.8 · Published 2026-04-06

Vendors: Tenda.

Executive brief

A vulnerability has been identified in the Tenda i12 wireless access point, a device used to provide Wi-Fi connectivity in business and home environments. An attacker can exploit a flaw in how the device handles network configuration settings to crash the system or potentially take full control of the device. This could lead to a total loss of internet connectivity for users or allow an attacker to intercept network traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda i12 access point (firmware version 1.0.0.11(3862)) within the 'httpd' binary. The flaw is located in the 'formwrlSSIDset' function in the '/goform/wifiSSIDset' handler. The vulnerability is triggered when the 'wl_radio' parameter is set to 0, causing the 'index' parameter to be processed by 'sprintf' into a fixed-size stack buffer without length validation. An authenticated remote attacker can exploit this by sending a specially crafted POST request to overwrite the stack, leading to a denial of service (DoS) or arbitrary remote code execution (RCE). A public exploit (PoC) is available.

Affected products

  • Tenda i12 1.0.0.11(3862)

Timeline

  • 2026-04-06: disclosed: Initial disclosure of the vulnerability
  • 2026-04-06: advisory: NVD publication date

References