CVE-2026-13518: Tenda JD12L addressNat fromAddressNat stack-based overflow
Published Jun 29, 2026
·Updated
A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Tenda JD12L=16.03.53.23
Event History
Jun 29, 2026
CVE Published
via MITRE·12:15 AM
Data Sourced
via MITRE·12:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-13518?
CVE-2026-13518 has a high severity rating of 8.8.
2
How do I fix CVE-2026-13518?
To fix CVE-2026-13518, update the Tenda JD12L firmware to the latest version that addresses the vulnerability.
3
What type of vulnerability is represented by CVE-2026-13518?
CVE-2026-13518 is a stack-based buffer overflow vulnerability.
4
Can CVE-2026-13518 be exploited remotely?
Yes, CVE-2026-13518 allows for remote exploitation.
5
What functions are affected by CVE-2026-13518?
The vulnerability affects the fromAddressNat function in the addressNat file of Tenda JD12L.