CVE-2026-5989
8.8Tenda · F451
A stack-based buffer overflow in the Tenda F451 router allows remote attackers to trigger memory corruption via the page argument in the /goform/RouteStatic endpoint.
Executive summary
A critical stack-based buffer overflow vulnerability in the Tenda F451 router allows remote code execution, posing a significant risk to network integrity.
Vulnerability
This vulnerability is a stack-based buffer overflow (CWE-121) occurring in the fromRouteStatic function within the /goform/RouteStatic file. An authenticated attacker can trigger this memory corruption by manipulating the page argument, which can be executed remotely.
Business impact
The exploitation of this vulnerability can lead to a full compromise of the affected routing device. Given the CVSS score of 8.8, this flaw represents a high risk as it allows for unauthorized code execution, potentially enabling lateral movement within the network, interception of traffic, or total loss of device availability, which could severely disrupt business operations.
Remediation
Immediate Action: Since a specific patch version is not currently identified, users should restrict administrative access to the device interface and disable remote management features until the vendor provides a firmware update.
Proactive Monitoring: Monitor network traffic for unusual patterns directed at the /goform/RouteStatic endpoint and review device system logs for signs of repeated crashes or unauthorized configuration changes.
Compensating Controls: Deploy a Web Application Firewall or network-level access control lists to filter traffic to the management interface, ensuring only trusted IP addresses can interact with the vulnerable endpoint.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the research write-up at https://github.com/Jimi-Lab/cve/issues/5.
Analyst recommendation
The severity of this buffer overflow requires immediate attention from network administrators. Given the availability of a public proof-of-concept, the risk of exploitation is elevated. Organizations should prioritize isolating the affected Tenda F451 units from public-facing networks until the vendor releases a firmware patch that addresses the memory corruption issue in the fromRouteStatic function.
More Tenda CVEs
Sources
Originally found and disclosed by Jimi (VulDB User), per the CVE Program record.
- VDB-356543 | Tenda F451 RouteStatic fromRouteStatic stack-based overflow Vulnerability database entry
- VDB-356543 | CTI Indicators (IOB, IOC, IOA)
- Submit #792858 | Tenda F451_kfw_V1.0.0.7_cn_svn7958 V1.0.0.7 Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn