CVE-2025-11550
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-09

Last updated on: 2026-04-29

Assigner: VulDB

Description
A vulnerability was found in Tenda W12 3.0.0.6(3948). The impacted element is the function wifiScheduledSet of the file /goform/modules of the component HTTP Request Handler. The manipulation of the argument wifiScheduledSet results in null pointer dereference. The attack may be performed from remote. The exploit has been made public and could be used.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-09
Last Modified
2026-04-29
Generated
2026-05-07
AI Q&A
2025-10-09
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
tenda w12_firmware 3.0.0.6\(3948\)
tenda w12 3.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the Tenda W12 firmware version 3.0.0.6(3948), specifically in the wifiScheduledSet function within the HTTP Request Handler component. Manipulating the wifiScheduledSet argument can cause a null pointer dereference, which may lead to a denial of service or crash. The attack can be performed remotely, and an exploit is publicly available.


How can this vulnerability impact me? :

The vulnerability can be exploited remotely to cause a null pointer dereference, potentially resulting in denial of service or crashing the affected device. This could disrupt network connectivity or device availability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart