CVE-2026-15694: Tenda BE12 Pro SetIpBind fromSetIpBind stack-based overflow
Published Jul 14, 2026
·Updated
A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used.
Affected Software
1 affected component
Tenda BE12 Pro=16.03.66.23
Event History
Jul 14, 2026
CVE Published
via MITRE·02:15 PM
Data Sourced
via MITRE·02:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-15694?
The severity of CVE-2026-15694 is high, with a score of 8.8.
2
How do I fix CVE-2026-15694?
To fix CVE-2026-15694, update your Tenda BE12 Pro device to the latest firmware version that addresses this vulnerability.
3
What type of vulnerability is CVE-2026-15694?
CVE-2026-15694 is a stack-based buffer overflow vulnerability.
4
Can CVE-2026-15694 be exploited remotely?
Yes, CVE-2026-15694 can be exploited remotely, allowing an attacker to manipulate the affected function.
5
Which function is affected by CVE-2026-15694?
The function affected by CVE-2026-15694 is fromSetIpBind in the Tenda BE12 Pro firmware.