Impact
A stack-based buffer overflow occurs in the fromSafeMacFilter function of the /goform/SafeMacFilter web interface on the Tenda BE12 Pro. By manipulating the page argument, an attacker can trigger the overflow and potentially inject executable code or overwrite data on the stack, giving code execution privileges on the device.
Affected Systems
The vulnerability affects Tenda BE12 Pro routers running firmware 16.03.66.23. Only devices with this specific build that remain exposed to the web interface at /goform/SafeMacFilter are impacted.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high-severity flaw. The EPSS score of less than 1% indicates a low present exploitation probability. It is not listed in the CISA KEV catalog. The attack vector is remote over the network via the router’s administrative interface; local or privileged access is not required according to the description. Consequently, an attacker who can reach the web interface could exploit the overflow to execute code on the device.
OpenCVE Enrichment