A vulnerability classified as critical was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). Affected by this vulnerability is the function cgidhcpsCfgSet of the file /goform/modules of the component httpd. The manipulation of the argument json leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
2025-04-28T08:15:16.117
2025-07-30T18:57:09.823
Analyzed
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | tenda | w12_firmware | 3.0.0.4\(2887\) | Yes |
Hardware | tenda | w12 | - | No |
Operating System | tenda | w12_firmware | 3.0.0.5\(3644\) | Yes |
Hardware | tenda | w12 | - | No |
Operating System | tenda | i24_firmware | 3.0.0.4\(2887\) | Yes |
Hardware | tenda | i24 | - | No |
Operating System | tenda | i24_firmware | 3.0.0.5\(3644\) | Yes |
Hardware | tenda | i24 | - | No |