Description
A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2026-05-30: | Advisory disclosed |
| 2026-05-30: | VulDB entry created |
| 2026-05-30: | VulDB entry last update |
Credits
CookedMelon (VulDB User)
References
vuldb.com/submit/820022
vuldb.com/vuln/367471 (VDB-367471 | Tenda W12 Web Management httpd cgiSysWebTimeoutSet denial of service)
vuldb.com/vuln/367471/cti (VDB-367471 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10190 (CVE-2026-10190 | CVE Analysis and Report)
vuldb.com/submit/820022 (Submit #820022 | Tenda W12 V3.0.0.7(4763) Denial of Service)
cdn2.v50to.cc/cgiSysWebTimeoutSet_dos.zip
www.tenda.com.cn/