Junglewise Threat Intelligence

CVE-2026-5684: Tenda CX12L stack overflow in fromwebExcptypemanFilter

CVE-2026-5684 · Severity: high · CVSS 8 · Published 2026-04-06

Technologies: Tenda Cx12l, Tenda Cx12l Firmware, Tenda CX12L Router. Vendors: Tenda.

Executive brief

A security vulnerability exists in the Tenda CX12L router, a device used to provide wireless internet connectivity. An attacker on the local network can exploit this flaw to crash the router or potentially take full control of the device. This could lead to a complete loss of internet access, monitoring of network traffic, or unauthorized access to other devices connected to the same network.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda CX12L router (firmware 16.03.53.12) within the 'fromwebExcptypemanFilter' function of the '/goform/webExcptypemanFilter' endpoint. The root cause is the unsafe use of 'sprintf' when processing the user-controlled 'page' parameter, which is copied into a fixed-size 256-byte buffer without length validation. An attacker with local network access can send a specially crafted POST request with an oversized 'page' argument to overwrite adjacent memory on the stack. Successful exploitation can lead to a Denial of Service (DoS) by crashing the web server or arbitrary code execution by overwriting return addresses. A public PoC is available.

Affected products

  • Tenda CX12L Router 16.03.53.12

Timeline

  • 2026-03-30: disclosed: Vulnerability details and PoC shared on GitHub.
  • 2026-04-06: advisory: CVE-2026-5684 published.

References

Related threats