CVE-2026-5849: Tenda i12 Firmware
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected products
- Tenda i12 Firmware: version 1.0.0.11(3862) only
Published 2026-04-09. Last modified 2026-06-17.