Executive brief
A security vulnerability has been identified in the Tenda JD12L Pro router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to crash the router's management interface or potentially take full control of the device. This could allow an unauthorized user to monitor network traffic or use the compromised router as a jumping-off point to attack other devices on the home or business network.
Technical details
A stack-based buffer overflow exists in the Tenda JD12L Pro router (firmware version 16.03.53.23) within the 'fromSetWifiGusetBasic' function of the '/goform/WifiGuestSet' endpoint. The vulnerability is caused by the unsafe use of the 'strcpy' function when parsing the 'shareSpeed' parameter, which lacks proper bounds checking. A remote attacker can exploit this by sending a specially crafted POST request with an oversized 'shareSpeed' value to overwrite the program's stack. Successful exploitation can lead to a Denial of Service (DoS) by crashing the web server process or arbitrary code execution by hijacking the program's return address. While some reports suggest authentication may be required (PR:L), a public Proof of Concept (PoC) indicates it may be triggerable without authentication.
Affected products
- Tenda JD12L Pro 16.03.53.23
Timeline
- 2026-05-27: disclosed: Initial discovery and report on GitHub
- 2026-06-29: advisory: CVE published to NVD dataset