Description
A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Published: 2026-05-31
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the web management interface of the Tenda W12 router allows an attacker to manipulate the web_over_time parameter in the cgiSysWebTimeoutSet CGI handler, leading to a denial of service condition that can reach the router’s web server process. This vulnerability is classified as a failure to properly handle abnormal input and results in the web service becoming unreachable, disrupting administrative access and potentially affecting network traffic routed through the device.

Affected Systems

The affected product is the Tenda W12 router running firmware version 3.0.0.7 (build 4763). No other vendors or product variants are listed as impacted.

Risk and Exploitability

The CVSS score of 7.1 categorizes this problem as high severity. The EPSS score is not available, but the vulnerability is publicly documented and the exploit code has been released, indicating that attackers could realistically target any exposed device. The attack vector is remote, using HTTP requests to the router’s management interface, and the vulnerability is not listed in CISA’s KEV catalog, yet the ability to cause service disruption makes it a pressing risk for any network relying on this device.

Generated by OpenCVE AI on May 31, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Tenda firmware update that addresses the cgiSysWebTimeoutSet issue; if an official patch is not yet available, contact Tenda support for a fix or a detailed recommendation.
  • Restrict access to the router’s web management interface by implementing firewall rules that allow only trusted IP addresses, or place the device on a separate management VLAN to limit exposure.
  • Monitor the router for abnormal CPU usage or web server failures and configure automatic restarts or alerting if the management service becomes unavailable.

Generated by OpenCVE AI on May 31, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 01 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 31 May 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda w12
Vendors & Products Tenda w12

Sun, 31 May 2026 16:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Title Tenda W12 Web Management httpd cgiSysWebTimeoutSet denial of service
First Time appeared Tenda
Tenda w12 Firmware
Weaknesses CWE-404
CPEs cpe:2.3:o:tenda:w12_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda w12 Firmware
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-01T15:04:52.891Z

Reserved: 2026-05-30T16:45:13.485Z

Link: CVE-2026-10190

cve-icon Vulnrichment

Updated: 2026-06-01T15:04:24.210Z

cve-icon NVD

Status : Deferred

Published: 2026-05-31T16:16:41.387

Modified: 2026-06-01T17:16:40.917

Link: CVE-2026-10190

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-31T17:30:08Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release