Tenda CX12L是中国腾达(Tenda)公司的一款家用无线路由器设备。 Tenda CX12L 16.03.53.12版本存在缓冲区错误漏洞,该漏洞源于Wi-Fi Schedule Configuration Endpoint组件文件/goform/openSchedWifi中函数setSchedWifi对参数schedStartTime/schedEndTime的操作,可能导致栈缓冲区溢出。攻击者可远程发起攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-11499 | 9.8 CRITICAL | Tenda HG7HG9/HG10 formDOMAINBLK stack-based overflow |
| CVE-2026-11498 | 8.8 HIGH | Tenda HG7HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow |
| CVE-2026-11503 | 8.8 HIGH | Tenda CX12L Wi-Fi Configuration Endpoint fast_setting_wifi_set form_fast_setting_wifi_set |
| CVE-2026-11522 | 8.8 HIGH | Tenda W20E setPortMirror formSetPortMirror stack-based overflow |
| CVE-2026-11523 | 8.8 HIGH | Tenda W20E Web Management PortalAuth formPortalAuth stack-based overflow |
| CVE-2026-11524 | 8.8 HIGH | Tenda W20E Web Management modifyWifiFilterRules stack-based overflow |
| CVE-2026-11528 | 8.8 HIGH | Tenda AC18 Web Management getRebootStatus sub_45304 stack-based overflow |
| CVE-2026-11553 | 8.8 HIGH | Tenda HG7HG9/HG10 formPPPEdit stack-based overflow |
| CVE-2026-11556 | 8.8 HIGH | Tenda F451 Web Management WriteFacMac formWriteFacMac os command injection |
| CVE-2026-11557 | 8.8 HIGH | Tenda F451 Web Management Natlimit fromNatlimit stack-based overflow |
| CVE-2026-11493 | 5.0 MEDIUM | Tenda AC15 Samba smb.conf weak password |
No comments yet