CVE-2026-10190
A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the comp
CVSS
6.5
Medium
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Published: May 31, 2026 · Last modified: Jul 22, 2026 · CWE-404
0.4%EPSS · 30 days0.4%
2026-08-202026-09-18
A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the attack remotely. The exploit has been made public and could be used.
- cdn2.v50to.cchttp://cdn2.v50to.cc/cgiSysWebTimeoutSet_dos.zip
- vuldb.comhttps://vuldb.com/cve/CVE-2026-10190
- vuldb.comhttps://vuldb.com/submit/820022
- vuldb.comhttps://vuldb.com/vuln/367471
- vuldb.comhttps://vuldb.com/vuln/367471/cti
- www.tenda.com.cnhttps://www.tenda.com.cn/
- vuldb.comhttps://vuldb.com/submit/820022
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-928814.3 MED27.2%
——8A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory of the file src/meta/awb.c of the component AWB parser. Such manipulation leads to divide by zero. The attack can be executed remotely. The name of the patch is ae37662ad626254ddd96ad69ac263792d7a92024. A patch should be applied to remediate this issue.23hCVE-2026-928794.3 MED37.3%
——11A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in resource consumption. The attack may be launched remotely. The patch is identified as ae37662ad626254ddd96ad69ac263792d7a92024. Applying a patch is advised to resolve this issue.23hCVE-2026-924176.5 MED49.3%
——15A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack may be launched remotely. The patch is identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2. A patch should be applied to remediate this issue.2dCVE-2026-924134.3 MED37.2%
——11A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation can lead to null pointer dereference. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e. Applying a patch is advised to resolve this issue.57mCVE-2026-923654.3 MED32.6%
——10A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.2dCVE-2026-923634.3 MED43.2%
——13A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. This patch is called ab6e0bc298996caac2b4b0b3ec0bd8d32a15a186. Applying a patch is advised to resolve this issue.2h