Executive brief
A security vulnerability has been identified in the Tenda BE12 Pro router, a device used to provide wireless internet connectivity for homes and small offices. An attacker can exploit this flaw to crash the router's management interface or potentially take full control of the device. This could allow an unauthorized user to monitor network traffic, access sensitive data, or use the compromised router to launch further attacks on other devices within the network.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda BE12 Pro router (firmware version 16.03.66.23) within the '/goform/DhcpListClient' endpoint. The root cause is the unsafe use of the 'sprintf' function in the 'fromDhcpListClient' function, which processes the user-controlled 'page' parameter without adequate length validation. The destination buffer is fixed at 256 bytes, and providing a larger input allows an attacker to overwrite adjacent stack memory. While the advisory suggests the attack can be initiated remotely and provides a proof-of-concept that does not include authentication headers, the CVSS vector indicates low privileges (PR:L) may be required. Successful exploitation can lead to a Denial of Service (DoS) of the web management interface or arbitrary code execution.
Affected products
- Tenda BE12 Pro 16.03.66.23
Timeline
- 2026-06-11: disclosed: Vulnerability details and PoC shared on GitHub.
- 2026-07-14: advisory: CVE published by NVD/VulDB.