PT-2026-45201 · Tenda · W12

Cookedmelon

·

Published

2026-05-31

·

Updated

2026-05-31

·

CVE-2026-10190

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web over time results in denial of service. It is possible to launch the attack remotely. The exploit has been made public and could be used.

Exploit

Fix

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2026-10190

Affected Products

W12