CVE-2026-5990

8.8

Tenda · F451

A stack-based buffer overflow in the Tenda F451 function fromSafeEmailFilter allows remote attackers to trigger memory corruption via the page argument.

Executive summary

A critical stack-based buffer overflow in Tenda F451 allows remote code execution, posing a significant risk of total system compromise.

Vulnerability

This vulnerability is a stack-based buffer overflow located in the fromSafeEmailFilter function within the /goform/SafeEmailFilter file. An authenticated attacker can trigger the overflow by manipulating the page argument, leading to potential memory corruption or remote code execution.

Business impact

The exploitation of this vulnerability could lead to total loss of system integrity and availability, as the buffer overflow allows for arbitrary code execution. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could be leveraged to gain unauthorized control over network infrastructure, potentially facilitating lateral movement within the environment.

Remediation

Immediate Action: Contact Tenda support or monitor the official Tenda website for the release of a firmware update that addresses the buffer overflow in the SafeEmailFilter component.

Proactive Monitoring: Review device access logs for unusual traffic patterns directed at the /goform/SafeEmailFilter endpoint, specifically monitoring for abnormally long strings in the page parameter.

Compensating Controls: Implement strict network access control lists to limit management interface access to trusted internal IP addresses, thereby reducing the attack surface for remote exploitation.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists, as documented in the technical write-up provided by Jimi-Lab.

Analyst recommendation

Due to the availability of a public proof-of-concept and the high severity of memory corruption vulnerabilities, immediate action is required. Organizations utilizing the Tenda F451 should restrict network access to the device and prioritize applying firmware updates as soon as they are made available by the vendor to prevent potential exploitation.

More Tenda CVEs

Sources

Originally found and disclosed by Jimi (VulDB User), per the CVE Program record.