CVE-2026-15692: Tenda BE12 Pro

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

Affected products

  • Tenda BE12 Pro: version 16.03.66.23 only

Published 2026-07-14. Last modified 2026-07-14.