Junglewise Threat Intelligence

CVE-2026-15693: Tenda BE12 Pro stack buffer overflow in fromSafeMacFilter

CVE-2026-15693 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Tenda BE12 Pro. Vendors: Tenda.

Executive brief

A security vulnerability exists in the Tenda BE12 Pro router, a device used for home and business networking. An attacker can exploit this flaw to cause the router to crash or potentially take full control of the device. This could lead to the monitoring of network traffic, theft of sensitive data, or the use of the router as a jumping-off point to attack other devices on the same network.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda BE12 Pro router (firmware version 16.03.66.23) within the 'fromSafeMacFilter' function of the '/goform/SafeMacFilter' endpoint. The root cause is the unsafe use of 'sprintf' when processing the user-controlled 'page' parameter, which writes data into a fixed-size 256-byte buffer without length validation. An attacker can exploit this by sending a specially crafted POST request with an oversized 'page' parameter. Successful exploitation can lead to memory corruption, denial of service (DoS) by crashing the web server, or arbitrary code execution by overwriting the return address on the stack. While some reports suggest the attack is possible without authentication, the CVSS vector indicates low privileges may be required.

Affected products

  • Tenda BE12 Pro 16.03.66.23

Timeline

  • 2026-06-11: disclosed: Vulnerability details and PoC shared on GitHub.
  • 2026-07-14: advisory: CVE-2026-15693 published.

References

Related threats