CVE-2026-13515: Tenda JD12L Stack Buffer Overflow in PPTP Server Configuration
Tenda JD12L router version 16.03.53.23 contains a stack-based buffer overflow vulnerability in its PPTP server configuration function. An authenticated attacker can exploit this flaw by sending a specially crafted request with an oversized startIp parameter, potentially causing the application to crash or allowing arbitrary code execution. The vulnerability is reachable over the network and has been publicly disclosed.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-119, CWE-121
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-29 / 2026-06-29
NVD description (verbatim)
A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. Such manipulation of the argument startIp leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-13515 is a stack-based buffer overflow (CWE-119, CWE-121) in the formSetPPTPServer function located at /goform/SetPptpServerCfg on Tenda JD12L firmware version 16.03.53.23. The vulnerability exists due to insufficient bounds checking on the startIp argument, allowing an authenticated remote attacker to write beyond allocated stack memory. This can lead to stack corruption, denial of service, or control flow hijacking depending on the target architecture and memory layout.
Business impact
Compromise of a Tenda JD12L router can lead to network segmentation bypass, interception of traffic, unauthorized access to connected resources, or denial of service affecting all devices on the network. For organizations relying on these devices for remote access or branch office connectivity via PPTP, exploitation could disrupt business continuity and expose sensitive traffic to eavesdropping.
Affected systems
Tenda JD12L firmware version 16.03.53.23 is confirmed affected. Organizations should verify whether this specific firmware version is deployed in their environment. Tenda has not provided a list of additional affected versions or models in the available advisory data; verify against the vendor's security bulletin for a complete compatibility matrix.
Exploitability
The vulnerability requires authentication (consistent with the CVSS vector PR:L designation), meaning an attacker must first obtain valid credentials. However, the attack is trivial to execute once authenticated—no user interaction is required and exploitation can be performed entirely remotely. Public disclosure of this vulnerability increases the likelihood of weaponization by malicious actors with internal network access or compromised credentials.
Remediation
Upgrade Tenda JD12L to a patched firmware version released after 16.03.53.23. Consult Tenda's official security advisories and firmware download page to identify the specific patched build for your model. As an interim mitigation, restrict access to the web management interface to trusted administrative networks using firewall rules or access control lists.
Patch guidance
Visit Tenda's official support portal and locate the latest firmware release for the JD12L model. Verify the version number exceeds 16.03.53.23 before deployment. Firmware updates typically require a network-accessible device and can be performed through the web interface; document any configuration backups before updating. Verify against the vendor advisory that the specific patch version addresses CVE-2026-13515.
Detection guidance
Monitor network traffic for HTTP POST requests to /goform/SetPptpServerCfg with unusually large or malformed startIp parameter values. Log access to the router's web management interface and review authentication logs for suspicious login activity, especially from unexpected source IPs. Use intrusion detection signatures targeting stack-based buffer overflows in Tenda firmware if available from your IDS vendor. Inspect router logs for any signs of application crashes or restarts correlated with configuration change attempts.
Why prioritize this
With a CVSS score of 8.8 (HIGH) and public disclosure, this vulnerability warrants urgent attention despite the authentication requirement. The combination of remote exploitability, high confidentiality/integrity/availability impact, and known public exploit code makes it attractive to adversaries with initial network access. Organizations should prioritize patching or implementing compensating controls within 7–14 days.
Risk score, explained
The CVSS 3.1 score of 8.8 reflects high impact across confidentiality, integrity, and availability (C:H/I:H/A:H), network-accessible attack vector (AV:N), and low attack complexity (AC:L). The primary limiting factor is the requirement for low-privilege authentication (PR:L), which prevents remote unauthenticated exploitation. In environments where administrative credentials are shared, weak, or compromised, this distinction erodes rapidly.
Frequently asked questions
Does this vulnerability affect other Tenda router models?
The advisory specifies Tenda JD12L version 16.03.53.23. Other Tenda models may contain similar PPTP server implementations and could be vulnerable; contact Tenda support or check their security bulletins to determine if your other devices require updates.
Can this vulnerability be exploited without network access to the router's web interface?
No. Exploitation requires authentication and direct access to the /goform/SetPptpServerCfg endpoint. An attacker must either obtain valid admin credentials or compromise a device already on your network that can reach the router's management interface.
What should we do if we cannot patch immediately?
Restrict access to the router's web management interface (typically port 80/443) to a dedicated administrative VLAN or IP whitelist. Disable PPTP services if not in use. Monitor logs closely for authentication anomalies. Implement a 30-day remediation timeline and document the business justification for any delay.
Is this vulnerability included in CISA's Known Exploited Vulnerabilities (KEV) catalog?
No, CVE-2026-13515 is not currently listed in the CISA KEV catalog. However, public exploit disclosure exists, so it may be added in the future. Treat this as actively exploitable and do not delay remediation.
This analysis is based on the CVE entry and publicly available technical information as of June 2026. Patch versions and detailed remediation steps must be verified against Tenda's official security advisories and firmware release notes. SEC.co does not provide exploit code or step-by-step weaponization guidance. Organizations are responsible for testing patches in non-production environments before deployment. Severity assessment assumes standard network architectures; your actual risk may differ based on network segmentation, access controls, and threat model. Source: NVD (public-domain), retrieved 2026-08-07. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10062HIGHTRENDnet TEW-432BRP Stack Overflow – EOL Hardware Risk
- CVE-2026-10063HIGHTRENDnet TEW-432BRP Stack Overflow – End-of-Life Router Vulnerability
- CVE-2026-10065HIGHShibby Tomato 1.28 Stack Buffer Overflow in tomatodata.cgi
- CVE-2026-10066HIGHShibby Tomato Stack Buffer Overflow in UPS Service (RCE)
- CVE-2026-10067HIGHShibby Tomato 1.28 Stack Buffer Overflow in multimon.cgi
- CVE-2026-10119HIGHStack Overflow in TRENDnet TEW-432BRP End-of-Life Router
- CVE-2026-10120HIGHTRENDnet TEW-432BRP Buffer Overflow – No Patch Available
- CVE-2026-10121HIGHTRENDnet TEW-432BRP Stack Buffer Overflow