Impact
A stack‑based buffer overflow has been identified in the fromVirtualSer function within the /goform/VirtualSer endpoint of Tenda BE12 Pro routers. Manipulating the arguments supplied to this function can corrupt the call stack, potentially allowing an attacker to execute arbitrary code on the device. The vulnerability is classified under CWE‑119 and CWE‑121, indicating a classic memory corruption error that compromises the confidentiality, integrity, and availability of the affected device.
Affected Systems
The vulnerability affects Tenda BE12 Pro routers running firmware version 16.03.66.23.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating high severity, while its EPSS score of less than 1 % suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, but an exploit has been publicly disclosed and can be triggered remotely through standard HTTP requests to the management interface, enabling attackers to gain control of the device.
OpenCVE Enrichment