Junglewise Threat Intelligence

CVE-2026-15696: Tenda BE12 Pro stack buffer overflow in /goform/VirtualSer

CVE-2026-15696 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Tenda BE12 Pro. Vendors: Tenda.

Executive brief

A vulnerability exists in the Tenda BE12 Pro router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to crash the router's management interface or potentially take full control of the device. This could allow an unauthorized user to monitor network traffic or use the router as a jumping-off point to attack other devices on the internal network.

Technical details

A stack-based buffer overflow vulnerability exists in Tenda BE12 Pro firmware version 16.03.66.23. The issue is located in the 'fromVirtualSer' function within the '/goform/VirtualSer' endpoint, where the user-supplied 'page' parameter is processed using the unsafe 'sprintf' function. Because the destination buffer is fixed at 256 bytes and lacks length validation, an attacker can provide an oversized input to overwrite adjacent stack memory. This can be exploited remotely to achieve arbitrary code execution or a denial of service (DoS) by crashing the web server process. A public proof-of-concept exists demonstrating the overflow using a 2048-byte payload.

Affected products

  • Tenda BE12 Pro 16.03.66.23

Timeline

  • 2026-06-11: disclosed: Initial disclosure on GitHub by researcher dexingzhiqing
  • 2026-07-14: advisory: NVD/VulDB advisory published

References

Related threats