CVE-2026-3679
8.8Tenda · FH451
A stack-based buffer overflow in the Tenda FH451 router allows remote attackers to trigger memory corruption and potential code execution via the formQuickIndex function.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda FH451 firmware version 1.0.0.9 poses a high risk of remote code execution or denial of service.
Vulnerability
This vulnerability is a stack-based buffer overflow located in the formQuickIndex function within the /goform/QuickIndex file. By sending a specially crafted POST request containing excessively long inputs in the mit_linktype or PPPOEPassword parameters, a low-privileged authenticated attacker can trigger memory corruption, potentially leading to remote code execution or system instability.
Business impact
The exploitation of this vulnerability could lead to a total compromise of the affected router, allowing an attacker to gain unauthorized control over network traffic or disrupt critical business connectivity. Given the CVSS score of 8.8, this flaw represents a significant risk to organizational infrastructure, as successful exploitation results in complete loss of confidentiality, integrity, and availability for the affected device.
Remediation
Immediate Action: Since no official patch is currently available, administrators should immediately restrict access to the management interface of the Tenda FH451 device to trusted internal management networks only.
Proactive Monitoring: Monitor device logs for anomalous POST requests directed at the /goform/QuickIndex endpoint and watch for unexpected device reboots or service failures.
Compensating Controls: Deploy a Web Application Firewall or network-level access control list to filter or block requests containing abnormally long parameter values sent to the /goform/QuickIndex path.
Exploitation status
Public Exploit Available: Yes, a functional proof-of-concept has been published in the researcher's technical write-up on GitHub.
Analyst recommendation
Given the availability of a public proof-of-concept and the potential for remote code execution, this vulnerability poses a severe threat to network security. Organizations currently utilizing the Tenda FH451 should prioritize isolating these devices from external networks and remain vigilant for vendor-supplied firmware updates to remediate the underlying memory corruption flaw.
More Tenda CVEs
Sources
Originally found and disclosed by LtzHuster (VulDB User), per the CVE Program record.
- VDB-349581 | Tenda FH451 QuickIndex formQuickIndex stack-based overflow Vulnerability database entry
- VDB-349581 | CTI Indicators (IOB, IOC, IOA)
- Submit #765331 | Tenda FH451 V1.0.0.9 Stack-based Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn