Executive brief
A security vulnerability has been identified in the Tenda BE12 Pro router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to crash the router's management interface or potentially take full control of the device. This could allow an unauthorized user to monitor network traffic, access sensitive data, or use the router as a jumping-off point to attack other devices on the home or business network.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda BE12 Pro router (firmware version 16.03.66.23) within the 'fromSafeUrlFilter' function located in the '/goform/SafeUrlFilter' endpoint. The root cause is the unsafe use of the 'sprintf' function, which processes the user-controlled 'page' parameter into a fixed-size 256-byte buffer without adequate length validation. A remote attacker can exploit this by sending a specially crafted POST request with an oversized 'page' argument. Successful exploitation can lead to memory corruption, allowing for arbitrary code execution (via return address overwriting) or a Denial of Service (DoS) by crashing the web server process. While some metrics suggest low privileges are required, public PoC code indicates the vulnerability may be triggerable without authentication.
Affected products
- Tenda BE12 Pro 16.03.66.23
Timeline
- 2026-06-11: disclosed: Initial discovery and issue report on GitHub
- 2026-07-14: advisory: CVE published and NVD dataset updated