Junglewise Threat Intelligence

CVE-2026-13518: Tenda JD12L Pro stack buffer overflow in /goform/addressNat

CVE-2026-13518 · Severity: high · CVSS 8.8 · Published 2026-06-29

Technologies: Tenda JD12L Pro. Vendors: Tenda.

Executive brief

A vulnerability exists in the Tenda JD12L Pro router, a device used for home and small office networking. An attacker can exploit this flaw to crash the router's management interface or potentially take full control of the device. This could allow an unauthorized user to monitor network traffic or use the router as a jumping-off point to attack other devices on the private network.

Technical details

A stack-based buffer overflow vulnerability exists in the 'fromAddressNat' function within the '/goform/addressNat' endpoint of Tenda JD12L Pro firmware version 16.03.53.23. The root cause is the unsafe use of the 'sprintf' function when processing the user-controlled 'page' parameter, which writes data into a fixed-size 256-byte buffer without length validation. A remote attacker can trigger this overflow by sending a POST request with an oversized 'page' argument. Successful exploitation can lead to memory corruption, overwriting the return address on the stack to achieve arbitrary code execution or a denial of service (DoS). While some reports suggest low privileges are required, a public PoC indicates the endpoint may be reachable without authentication.

Affected products

  • Tenda JD12L Pro 16.03.53.23

Timeline

  • 2026-05-27: disclosed: Vulnerability details and PoC published on GitHub.
  • 2026-06-29: advisory: CVE published in NVD dataset.

References

Related threats