Impact
Tenda BE12 Pro routers running firmware 16.03.66.23 contain a stack-based buffer overflow in the /goform/DhcpListClient handler specifically in the function fromDhcpListClient. When an page argument, the function writes more data to a local buffer than the buffer can hold, corrupting the stack and potentially overwriting the return address. This flaw can be triggered entirely over the network and can lead to arbitrary code execution, a crash, denial of service, or a full compromise of the router control plane. The weakness is identified as CWE‑119 and CWE‑121.
Affected Systems
Only Tenda BE12 Pro routers with firmware version 16.03.66.23 are affected. No other vendors or product lines have been reported to be vulnerable by the CNA.
Risk and Exploitability
The CVSS base score of 8.7 classifies this issue as high severity, while the EPSS score of less than 1% indicates that exploitation is not common. The vulnerability is not listed in the CISA KEV catalog, but a publicly available exploit demonstrates that a remote attacker can trigger the overflow without local access, making it a tangible threat to device availability and integrity.
OpenCVE Enrichment