Impact
A flaw in the web management interface of the Tenda W12 router allows an attacker to manipulate the web_over_time parameter in the cgiSysWebTimeoutSet CGI handler, leading to a denial of service condition that can reach the router’s web server process. This vulnerability is classified as a failure to properly handle abnormal input and results in the web service becoming unreachable, disrupting administrative access and potentially affecting network traffic routed through the device.
Affected Systems
The affected product is the Tenda W12 router running firmware version 3.0.0.7 (build 4763). No other vendors or product variants are listed as impacted.
Risk and Exploitability
The CVSS score of 7.1 categorizes this problem as high severity. The EPSS score is not available, but the vulnerability is publicly documented and the exploit code has been released, indicating that attackers could realistically target any exposed device. The attack vector is remote, using HTTP requests to the router’s management interface, and the vulnerability is not listed in CISA’s KEV catalog, yet the ability to cause service disruption makes it a pressing risk for any network relying on this device.
OpenCVE Enrichment