CVE-2026-15691: Tenda BE12 Pro SafeClientFilter fromSafeClientFilter stack-based overflow
A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenda BE12 Pro SafeClientFilterto a version that resolves this vulnerability.Fixed in 16.03.66.23
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15691?
CVE-2026-15691 has a severity rating of 8.8, categorized as high.
What is the risk associated with CVE-2026-15691?
The risk associated with CVE-2026-15691 is classified as 78.
How do I fix CVE-2026-15691?
To fix CVE-2026-15691, apply the latest security updates released by Tenda for the BE12 Pro device.
What type of vulnerability is CVE-2026-15691?
CVE-2026-15691 is identified as a stack-based buffer overflow vulnerability.
Can CVE-2026-15691 be exploited remotely?
Yes, CVE-2026-15691 can be exploited remotely due to its nature.