CVE-2026-5849

HIGH

Tenda i12 HTTP path traversal

Title source: cna

Description

A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Scores

CVSS v3 7.3
EPSS 0.0008
EPSS Percentile 23.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-22
Status published
Products (1)
Tenda/i12 1.0.0.11(3862)
Published Apr 09, 2026
Tracked Since Apr 09, 2026