Executive brief
A security vulnerability exists in the Tenda JD12L Pro router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to crash the router's management interface or potentially take full control of the device. This could allow an unauthorized user to monitor network traffic or use the compromised router as a stepping stone to attack other devices on the local network.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda JD12L Pro router (firmware version 16.03.53.23) within the 'formSetPPTPServer' function of the '/goform/SetPptpServerCfg' endpoint. The vulnerability is caused by the unsafe use of the 'sscanf' function with an unbounded '%s' format specifier when parsing the 'startIp' parameter. A remote attacker can exploit this by sending a specially crafted POST request with an oversized 'startIp' value to overwrite the program's stack. Successful exploitation can lead to a denial of service (DoS) by crashing the web server or arbitrary code execution (ACE) by hijacking the program's execution flow. A public proof-of-concept exploit has been disclosed.
Affected products
- Tenda JD12L Pro 16.03.53.23
Timeline
- 2026-05-27: disclosed: Initial disclosure on GitHub by researcher cve-a
- 2026-06-29: advisory: NVD publication date