A vulnerability described as problematic has been identified in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service.

This vulnerability is known as CVE-2026-10190. It is possible to launch the attack remotely. Furthermore, an exploit is available.