CVE-2026-5991

8.8

Tenda · F451

Tenda F451 version 1.0.0.7 is vulnerable to a stack-based buffer overflow in the formWrlExtraSet function, which can be triggered remotely via the GO argument.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda F451 routers allows remote attackers to execute code via malicious input, posing a significant threat to device integrity.

Vulnerability

This vulnerability is a stack-based buffer overflow occurring within the formWrlExtraSet function of the /goform/WrlExtraSet endpoint. An authenticated attacker can trigger this memory corruption by manipulating the GO argument, potentially leading to arbitrary code execution.

Business impact

Successful exploitation of this buffer overflow could lead to a complete loss of control over the affected network device. Given the CVSS score of 8.8, the business impact includes the potential for unauthorized network access, interception of sensitive traffic, and total device compromise, which may result in significant operational downtime or lateral movement within the network.

Remediation

Immediate Action: Check the official Tenda support portal for firmware updates addressing this vulnerability and apply them immediately to all affected F451 units.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/WrlExtraSet endpoint and inspect device logs for unexpected reboots or crash events.

Compensating Controls: Restrict management access to the device to a trusted management network or VPN, and utilize a firewall to block unauthorized access to the web interface.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical report provided by the vulnerability researcher at the referenced GitHub repository.

Analyst recommendation

Due to the severity of this memory corruption vulnerability and the availability of a public proof-of-concept, users must prioritize the deployment of vendor security updates. If a patch is not currently available for your specific deployment, strict network segmentation is required to prevent remote access to the vulnerable administrative interface.

More Tenda CVEs

Sources

Originally found and disclosed by Jimi (VulDB User), per the CVE Program record.