Junglewise Threat Intelligence

CVE-2026-15691: Tenda BE12 Pro stack overflow in /goform/SafeClientFilter

CVE-2026-15691 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Tenda BE12 Pro. Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda BE12 Pro router, a device used for home and business networking. An attacker can exploit this flaw to crash the router's management interface or potentially take full control of the device. This could lead to unauthorized monitoring of network traffic or the use of the router as a foothold to attack other devices on the local network.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda BE12 Pro router (firmware version 16.03.66.23) within the 'fromSafeClientFilter' function of the '/goform/SafeClientFilter' endpoint. The root cause is the unsafe use of 'sprintf' to process the user-controlled 'page' parameter into a fixed-size 256-byte buffer without length validation. A remote attacker can exploit this by sending a specially crafted POST request with an oversized 'page' argument. Successful exploitation can lead to memory corruption, denial of service (DoS), or arbitrary code execution by overwriting the return address on the stack. A public exploit has been released.

Affected products

  • Tenda BE12 Pro 16.03.66.23

Timeline

  • 2026-06-11: disclosed: Vulnerability details shared on GitHub by researcher
  • 2026-07-14: advisory: CVE published to NVD dataset

References

Related threats