CVE-2026-4041 is a high-severity stack-based buffer overflow vulnerability affecting Tenda i12 1.0.0.6(2204) firmware, specifically within the vos_strcpy function of /goform/exeCommand when processing the 'cmdinput' argument. Rated 8.8 HIGH on CVSS, this flaw allows a low-privileged attacker to achieve remote code execution with low complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. Although not currently listed on CISA's KEV or Hot List, an exploit for this vulnerability has been publicly released, increasing the potential for future attacks despite minimal community discussion or media coverage to date.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.6\(2204\)CPE matchmatch criteria | cpe:2.3:o:tenda:i12_firmware:1.0.0.6\(2204\):*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.