CVE-2026-5992
8.8Tenda · F451
A stack-based buffer overflow in Tenda F451 version 1.0.0.7 allows remote attackers to trigger memory corruption via the page argument in the fromP2pListFilter function.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda F451 routers could allow remote attackers to achieve unauthorized code execution or system crashes.
Vulnerability
The device is susceptible to a stack-based buffer overflow triggered via the page argument within the fromP2pListFilter function in the /goform/P2pListFilter endpoint. This vulnerability requires low privileges (authenticated) to execute, as indicated by the CVSS vector.
Business impact
The exploitation of this buffer overflow can lead to a full compromise of the affected router, resulting in potential unauthorized access to the network or complete device failure. Given the CVSS score of 8.8, this flaw represents a high risk to business continuity and internal network integrity, as it allows an attacker to manipulate core device memory.
Remediation
Immediate Action: Since a specific patch version is currently unknown, administrators should restrict network access to the management interface and verify if the vendor provides firmware updates via their official website.
Proactive Monitoring: Monitor device logs for anomalous traffic patterns directed at the /goform/P2pListFilter endpoint, which may indicate exploitation attempts.
Compensating Controls: Implement strict firewall rules to ensure that only authorized administrative IP addresses can access the router management interface, effectively mitigating remote exploitation vectors.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the GitHub issue referenced in the vulnerability disclosure.
Analyst recommendation
Given the availability of a public proof-of-concept and the high severity of memory corruption vulnerabilities, this issue poses a significant risk to affected environments. Organizations should prioritize isolating the affected hardware from external network exposure and monitor the vendor support portal for the release of a security patch to address this buffer overflow definitively.
More Tenda CVEs
Sources
Originally found and disclosed by Jimi (VulDB User), per the CVE Program record.