Remote stack-based buffer overflow in Tenda BE12 Pro SafeClientFilter

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-15691?

CVE-2026-15691 is a vulnerability classified as Stack-based Buffer Overflow and Improper Restriction of Operations within the Bounds of a Memory Buffer, affecting BE12 Pro (affected versions: 16.03.66.23). This vulnerability is rated High, with a CVSS score of 8.7. Public exploit code or evidence is available for this vulnerability, but that does not confirm exploitation in the wild.

Overview

Original source data

A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

Affected products and scope

  • Tenda BE12 Pro router firmware 16.03.66.23: affected.
  • The affected component is the fromSafeClientFilter function in /goform/SafeClientFilter.
  • No fixed release, parallel branch, or unaffected status for other versions is confirmed in the supplied record or the reviewed sources. The status of other versions therefore remains unknown.

Technical details

Tenda BE12 Pro processes attacker-controlled input in the /goform/SafeClientFilter endpoint through the fromSafeClientFilter function. The technical disclosure states that the page parameter is processed with sprintf and written into a fixed-size buffer named s, which is limited to 256 bytes without adequate length checks. Oversized input can overwrite adjacent stack memory, causing memory corruption and potentially crashing the service process. The flaw maps to CWE-121, and the supplied record also identifies CWE-119. The CNA record describes remote reachability with low privileges required, while the public PoC claims that authentication is not required; the actual authentication precondition is therefore unresolved and should not be assumed to be absent. Available evidence does not confirm that control-flow hijacking or arbitrary code execution is reliable in every deployment.

Exploitability

The flaw is remotely reachable and does not require physical or local access according to the published exploitation information. The record describes low attack complexity, no user interaction, and low privileges required. The public PoC claims that authentication is not required, which conflicts with the structured CNA assessment; the actual privilege requirement should be verified for each device and deployment. A public proof of concept is available, but the evidence confirms public exploitability only and does not establish exploitation in deployed environments.

Technical impact

The flaw causes stack memory corruption while the management endpoint processes attacker-controlled input. Direct consequences may include a service crash and loss of management interface availability; the public disclosure also describes information disclosure and arbitrary code execution as possible outcomes, but these results are not confirmed under every exploitation condition. If code execution is achieved, an attacker could alter router configuration, compromise device confidentiality and integrity, or use the router to reach related systems. Impact on devices connected behind the router has not been established by the available evidence.

Business impact

Exploitation may crash the management service and make device administration or related network services unavailable. Memory corruption could also alter program state or, if code execution is achieved, undermine the router's confidentiality and integrity. Because a router can sit at a central network boundary, successful compromise could enable configuration changes, traffic monitoring, or use of the device as a pivot toward other systems; these are possible consequences, not evidence of a specific intrusion. No fixed release is confirmed in the available evidence.

Remediation

  1. Confirm a corrected firmware release with Tenda and deploy it when available. No specific fixed release is confirmed at present, so do not infer that an arbitrary later version resolves the flaw.
  2. Until a confirmed fix is available, restrict the management interface and /goform/SafeClientFilter from the Internet and untrusted networks using firewall controls or network segmentation. Permit access only from required administrative networks.
  3. Review the device's authentication and administrative access controls because the available sources disagree on whether authentication is required for exploitation.
  4. If Tenda does not provide a suitable fix for the deployed device, evaluate replacement with a product that is supported and has a clear security update process.
  5. After updating or replacing the device, recheck the firmware version, administrative configuration, service health, and signs of unexpected reboot or configuration changes.

Detection

  1. Inventory Tenda BE12 Pro devices and verify their running firmware versions, prioritizing devices in the affected version scope.
  2. Determine whether the device management interface is reachable from the Internet or other untrusted networks, and assess reachability of /goform/SafeClientFilter.
  3. Review web, firewall, and network telemetry for unusual requests to the endpoint, especially requests containing an unusually large page parameter. This is precautionary monitoring, not a confirmed indicator.
  4. Check for service interruptions, unexpected reboots, network configuration changes, or administrative changes following requests to the endpoint.
  5. Inspect firmware and configuration integrity when a device crashes or behaves unexpectedly. The absence of matching log evidence does not prove that a device is safe.
Sources (18)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan