VYPR
High severity8.8NVD Advisory· Published May 31, 2026

CVE-2026-10191

CVE-2026-10191

Description

Stack-based buffer overflow in Tenda W12 router's cgiWifiMacFilterSet function allows remote unauthenticated attackers to execute arbitrary code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack-based buffer overflow in Tenda W12 router's cgiWifiMacFilterSet function allows remote unauthenticated attackers to execute arbitrary code.

Vulnerability

The vulnerability exists in Tenda W12 router firmware version 3.0.0.7(4763). The function cgiWifiMacFilterSet in the /bin/httpd binary is vulnerable to a stack-based buffer overflow when processing the wifiMacFilterSet.macList.mac argument. An attacker can send a specially crafted HTTP request to trigger the overflow. The affected product is the Tenda W12 router [1].

Exploitation

The attack can be initiated remotely without authentication. The attacker sends a malicious HTTP POST request to the vulnerable endpoint with an overly long value for the wifiMacFilterSet.macList.mac parameter. The exploit has been publicly disclosed, increasing the risk of active exploitation.

Impact

Successful exploitation allows an attacker to achieve arbitrary code execution on the device. Due to the stack-based nature, the attacker can overwrite return addresses and control program flow, potentially gaining full control of the router. This could lead to network compromise, data exfiltration, or use of the device in botnets.

Mitigation

As of the publication date (2026-05-31), no official patch has been released by Tenda. The vendor's website [1] does not provide a security advisory for this issue. Users should consider restricting remote access to the router's management interface, applying network segmentation, or replacing the device if possible. Monitor for firmware updates from Tenda.

AI Insight generated on May 31, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.