S.MANE//SEC × AI OPS
--:--:-- UTCHARDENED
← BACK TO WIRE
CVEHIGH2026-06-06

CVE-2026-10191: high vulnerability (CVSS 8.8)

CVE-2026-10191 affects Tenda W12 3.0.0.7(4763), allowing remote exploitation via cgiWifiMacFilterSet in /bin/httpd, leading to stack-based buffer overflow. Public exploit code is available, posing high risk (CVSS 8.8).

// OPERATOR NOTE — S.MANE

Given the remote exploitability and public disclosure, prioritize patching or mitigating this flaw in Tenda W12 devices. Monitor for active exploitation and consider network segmentation to limit exposure.

CVE-2026-10191 targets Tenda W12 routers running firmware version 3.0.0.7(4763). The vulnerability lies in the cgiWifiMacFilterSet function within /bin/httpd, which mishandles the wifiMacFilterSet.macList.mac argument, leading to a stack-based buffer overflow.

This flaw is remotely exploitable, making it a critical issue for exposed devices. Public disclosure of exploit code increases the likelihood of attacks, especially against unpatched systems.

Administrators should immediately apply firmware updates from Tenda or implement temporary mitigations, such as disabling remote management and isolating vulnerable devices from external networks.

#CVE-2026-10191