Impact
A stack‑based buffer overflow exists in the fromSafeUrlFilter function of the /goform/SafeUrlFilter endpoint on Tenda BE12 Pro firmware 16.03.66.23. Manipulating the page argument can corrupt the stack and potentially allow an attacker to execute arbitrary code. The vulnerability can be triggered from a remote source, giving an attacker the possibility of full control over the router’s firmware and configuration. This compromise would grant the attacker confidentiality, integrity, and availability breakage of the device and any network traffic passing through it.
Affected Systems
Tenda BE12 Pro router running firmware version 16.03.66.23. The vulnerability is specific to this product model and version; earlier or later firmware versions are not explicitly mentioned as affected.
Risk and Exploitability
The CVSS score of 8.7 denotes high severity. The EPSS score is reported as < 1%, indicating a low probability of exploitation at this time, and the vulnerability is not listed in CISA KEV. The likely attack vector is a remote HTTP request to the /goform/SafeUrlFilter endpoint with a crafted page parameter. An attacker would need network access to the router’s administrative interface, which is often exposed to the Internet or to an insecure local network.
OpenCVE Enrichment