2026-05-31 15:30CVE-2026-10190VulDB
PUBLISHED5.2Operating systemCWE-404

Tenda W12 Web Management httpd cgiSysWebTimeoutSet denial of service

A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the attack remotely. The exploit has been made public and could be used.

Problem type

Affected products

Tenda

W12

3.0.0.7(4763) - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-10190
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-10190",
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "dateUpdated": "2026-05-31T15:30:13.999Z",
    "dateReserved": "2026-05-30T16:45:13.485Z",
    "datePublished": "2026-05-31T15:30:13.999Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB",
        "dateUpdated": "2026-05-31T15:30:13.999Z"
      },
      "title": "Tenda W12 Web Management httpd cgiSysWebTimeoutSet denial of service",
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the attack remotely. The exploit has been made public and could be used."
        }
      ],
      "affected": [
        {
          "vendor": "Tenda",
          "product": "W12",
          "cpes": [
            "cpe:2.3:o:tenda:w12_firmware:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "Web Management Interface"
          ],
          "versions": [
            {
              "version": "3.0.0.7(4763)",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Denial of Service",
              "cweId": "CWE-404",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://vuldb.com/vuln/367471",
          "name": "VDB-367471 | Tenda W12 Web Management httpd cgiSysWebTimeoutSet denial of service",
          "tags": [
            "vdb-entry",
            "technical-description"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/367471/cti",
          "name": "VDB-367471 | CTI Indicators (IOB, IOC, TTP, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-10190",
          "name": "CVE-2026-10190 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/820022",
          "name": "Submit #820022 | Tenda W12 V3.0.0.7(4763) Denial of Service",
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "http://cdn2.v50to.cc/cgiSysWebTimeoutSet_dos.zip",
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.tenda.com.cn/",
          "tags": [
            "product"
          ]
        }
      ],
      "metrics": [
        {},
        {
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM"
          }
        },
        {
          "cvssV3_0": {
            "version": "3.0",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM"
          }
        },
        {
          "cvssV2_0": {
            "version": "2.0",
            "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:C/E:POC/RL:ND/RC:UR",
            "baseScore": 6.8
          }
        }
      ],
      "timeline": [
        {
          "time": "2026-05-30T00:00:00.000Z",
          "lang": "en",
          "value": "Advisory disclosed"
        },
        {
          "time": "2026-05-30T02:00:00.000Z",
          "lang": "en",
          "value": "VulDB entry created"
        },
        {
          "time": "2026-05-30T18:52:52.000Z",
          "lang": "en",
          "value": "VulDB entry last update"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "CookedMelon (VulDB User)",
          "type": "reporter"
        }
      ]
    }
  }
}