VULNERABILITY SUMMARY CVE-2026-5609 is a stack-based buffer overflow vulnerability affecting Tenda i12 version 1.0.0.11(3862) in the Parameter Handler component, specifically within the formwrlSSIDset function of the /goform/wifiSSIDset endpoint. The flaw stems from improper validation of the index/wl_radio parameter, allowing remote exploitation without requiring complex attack conditions. The vulnerability carries a CVSS 3.1 severity rating of 8.8 (HIGH), indicating significant risk. The attack vector is network-based, requires only low complexity, and demands user authentication but not user interaction. Successful exploitation could result in high-impact consequences across confidentiality, integrity, and availability, enabling attackers to potentially achieve remote code execution on affected routers. Exploit code has been publicly released and is available for use. However, the vulnerability currently shows minimal community attention, with a FAUCET Risk Score of 52.0/100 and is not included on CISA's Known Exploited Vulnerabilities catalog, suggesting it is not being actively leveraged in the wild at this time. Organizations operating Tenda i12 devices should nevertheless prioritize patching given the severity rating and availability of working exploits.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.11\(3862\)CPE matchmatch criteria | cpe:2.3:o:tenda:i12_firmware:1.0.0.11\(3862\):*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.