Tenda I12 Firmware vulnerabilities
9 known vulnerabilities affecting tenda/i12_firmware.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH6
Vulnerabilities
Page 1 of 1
CVE-2026-4042P2HIGHCVSS 8.8v1.0.0.6\(2204\)2026-03-12
CVE-2026-4042 [HIGH] CWE-119 CVE-2026-4042: A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function form
A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet. This manipulation of the argument index causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
nvd
CVE-2026-4041P2HIGHCVSS 8.8v1.0.0.6\(2204\)2026-03-12
CVE-2026-4041 [HIGH] CWE-119 CVE-2026-4041: A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy
A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
nvd
CVE-2026-5609P2HIGHCVSS 8.8v1.0.0.11\(3862\)2026-04-06
CVE-2026-5609 [HIGH] CWE-119 CVE-2026-5609: A flaw has been found in Tenda i12 1.0.0.11(3862). Affected by this vulnerability is the function fo
A flaw has been found in Tenda i12 1.0.0.11(3862). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component Parameter Handler. This manipulation of the argument index/wl_radio causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be
nvd
CVE-2026-4043P2HIGHCVSS 8.8v1.0.0.6\(2204\)2026-03-12
CVE-2026-4043 [HIGH] CWE-119 CVE-2026-4043: A security vulnerability has been detected in Tenda i12 1.0.0.6(2204). The impacted element is the f
A security vulnerability has been detected in Tenda i12 1.0.0.6(2204). The impacted element is the function formwrlSSIDget of the file /goform/wifiSSIDget. Such manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2026-5849P3CRITICALCVSS 9.8v1.0.0.11\(3862\)2026-04-09
CVE-2026-5849 [CRITICAL] CWE-22 CVE-2026-5849: A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown funct
A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2025-25678P3CRITICALCVSS 9.8v1.0.0.10\(3805\)2025-02-20
CVE-2025-25678 [CRITICAL] CWE-120 CVE-2025-25678: Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the funcpara1 parameter in
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.
nvd
CVE-2025-25676P3CRITICALCVSS 9.8v1.0.0.10\(3805\)2025-02-20
CVE-2025-25676 [CRITICAL] CWE-120 CVE-2025-25676: Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the list parameter in the
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.
nvd
CVE-2025-25679P3HIGHCVSS 8.0v1.0.0.10\(3805\)2025-02-20
CVE-2025-25679 [HIGH] CWE-121 CVE-2025-25679: Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.
nvd
CVE-2025-29149P3HIGHCVSS 7.5v1.0.0.10\(3805\)2025-03-20
CVE-2025-29149 [HIGH] CWE-121 CVE-2025-29149: Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the ping1 parameter in the
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.
nvd