Impact
A stack‑based buffer overflow exists in the fromSetIpBind function of the /goform/SetIpBind endpoint on the Tenda BE12 Pro. The flaw is triggered by manipulating the page parameter, allowing a remote attacker to overflow a stack buffer and execute arbitrary code on the device. The vulnerability is a classic memory corruption weakness, classified as CWE‑119 and CWE‑121.
Affected Systems
The reported product is the Tenda BE12 Pro running firmware 16.03.66.23. No other Tenda models, firmware versions, or builds have been identified as affected.
Risk and Exploitability
The CVSS v3 score of 8.7 indicates high severity. The EPSS score of less than 1 % indicates a low but non‑zero likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. Exploitation can be achieved by sending a crafted HTTP request to the /goform/SetIpBind endpoint with an abnormal page value. If successful the attacker gains code execution privileges on the appliance.
OpenCVE Enrichment