CVE-2026-4041
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to remotely execute malicious code on affected Tenda i12 devices by exploiting a flaw in how the device handles input commands, potentially taking control of the device. The attack can be carried out without needing physical access, making it particularly dangerous for users.
Technical Description
A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
CVSS Vector Analysis
Vector String
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Mar 12, 2026
27 days ago
Last Modified
Mar 12, 2026
26 days ago