CVE-2026-4043 describes a high-severity stack-based buffer overflow vulnerability affecting Tenda i12 1.0.0.6(2204) firmware. The flaw exists in the formwrlSSIDget function, allowing a remote attacker with low privileges to manipulate an argument and potentially achieve high impact on confidentiality, integrity, and availability. Rated with a CVSS score of 8.8, the attack vector is remote with low complexity and no user interaction required. Although not currently on CISA's KEV catalog or common exploit frameworks, the exploit has been publicly disclosed and may be used, with minimal community discussion observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.6\(2204\)CPE matchmatch criteria | cpe:2.3:o:tenda:i12_firmware:1.0.0.6\(2204\):*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.