CVE-2026-10190: Tenda w12
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Affected products
- Tenda w12: version 3.0.0.7(4763) only
Published 2026-05-31. Last modified 2026-07-22.