Impact
A stack‑based buffer overflow exists in the fromSafeClientFilter function of the /goform/SafeClientFilter file on Tenda BE12 Pro devices. By manipulating the page argument remotely, an attacker can corrupt the stack and redirect execution flow, allowing the execution of arbitrary code or a denial‑of‑service condition. The flaw is classified as CWE‑119 and CWE‑121.
Affected Systems
The vulnerability affects the Tenda BE12 Pro router running firmware version 16.03.66.23. No additional vendors or product variants are listed in the supplied data.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score of less than 1% implies a low current probability of widespread exploitation, yet the public release of exploit code raises concerns. The exploit is remote and does not require local victim interaction. The issue is not present in the CISA KEV catalog.
OpenCVE Enrichment