PT-2026-24959 · Tenda · Tenda I12
Jimi
·
Published
2026-02-28
·
Updated
2026-03-13
·
CVE-2026-4041
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda i12 version 1.0.0.6(2204)
Description
A security issue exists in Tenda i12 version 1.0.0.6(2204). The
vos strcpy function within the /goform/exeCommand file is susceptible to a stack-based buffer overflow. This occurs through manipulation of the cmdinput argument. The attack can be initiated remotely, and an exploit has been publicly released.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Stack Overflow
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda I12