CVE-2026-15696: Tenda BE12 Pro

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the file /goform/VirtualSer. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Affected products

  • Tenda BE12 Pro: version 16.03.66.23 only

Published 2026-07-14. Last modified 2026-07-14.