CVE-2026-4043

8.8

Tenda · i12

A stack-based buffer overflow in the Tenda i12 wifiSSIDget function allows remote attackers to trigger memory corruption via manipulation of the index argument.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda i12 firmware poses a significant risk of remote code execution or system instability.

Vulnerability

This vulnerability is a stack-based buffer overflow occurring within the formwrlSSIDget function in the /goform/wifiSSIDget file. It can be triggered by a remote attacker who provides a crafted index argument, requiring low privileges to execute.

Business impact

The exploitation of this memory corruption vulnerability could lead to a complete compromise of the affected wireless access point, resulting in unauthorized network access or total system failure. Given the CVSS score of 8.8, this flaw represents a high risk to organizational infrastructure, as it may be leveraged to pivot into internal network segments or intercept sensitive traffic.

Remediation

Immediate Action: Contact the vendor immediately to obtain a firmware update, as no official patch version is currently listed in the available data.

Proactive Monitoring: Monitor network traffic for unusual requests directed at the /goform/wifiSSIDget endpoint and review device logs for signs of process crashes or unauthorized configuration changes.

Compensating Controls: Restrict access to the management interface of the Tenda i12 device to trusted internal management subnets only and employ a firewall to block suspicious traffic patterns targeting the device.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up referenced by the CVE record (https://github.com/Jimi-Lab/cve/issues/3).

Analyst recommendation

Given the availability of a public proof-of-concept and the potential for full system compromise, administrators must treat this vulnerability with high priority. We strongly recommend isolating affected devices from the internet until a vendor-supplied firmware update is verified and installed to eliminate the underlying memory corruption flaw.

More Tenda CVEs

Sources

Originally found and disclosed by Jimi (VulDB User), per the CVE Program record.