CVE-2026-5609Disclosure(tenda / i12)

LOWCVSS 7.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in Tenda i12 1.0.0.11(3862). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component Parameter Handler. This manipulation of the argument index/wl_radio causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • i12
  • i12_firmware

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-06)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
i12i12_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-05: 1Mentions · 2026-04-06: 3Technical Details · 2026-04-06: 204-0504-06
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-051
Disclosure1
2026-04-063
Disclosure3
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5609 A flaw has been found in Tenda i12 1.0.0.11(3862). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component Parame… https://www.cve.org/CVERecord?id=CVE-2026-5609

    Post summary

    The text announces a new vulnerability (CVE-2026-5609) affecting Tenda i12 routers, noting the affected function but providing no exploitation details or patch information.

    00010396
    57.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5609 A flaw has been found in Tenda i12 1.0.0.11(3862). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component Parame… https://www.cve.org/CVERecord?id=CVE-2026-5609 ----- Traducción: CVE-2026-5609 Se … http://infoflow.cloud`

    Post summary

    The post announces a new CVE (CVE‑2026‑5609) affecting the Tenda i12 firmware, detailing the affected function and file but providing no PoC, exploit code, active exploitation claim, or patch information.

    0000034
    67 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5609: HIGH] Vulnerability found in Tenda i12 1.0.0.11(3862) allows remote attackers to trigger a stack-based buffer overflow via manipulation of argument index/wl_radio in the Parameter Handler compo...#cve,CVE-2026-5609,#cybersecurity https://cvefind.com/CVE-2026-5609

    Post summary

    The post announces a new high‑severity CVE-2026-5609 that enables remote attackers to trigger a stack‑based buffer overflow on the Tenda i12 router by manipulating specific arguments.

    0000045
    619 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Tenda i12 (CVE-2026-5609) https://vuldb.com/vuln/355400

    Post summary

    The post announces a newly identified vulnerability (CVE-2026-5609) affecting Tenda i12 via a VulDB link, without showing exploit, patch, or technical details.

    00000100
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendai12---
OStendai12_firmware1.0.0.11\(3862\)--

Explore more