CVE-2026-6120
8.8Tenda · F451
A stack-based buffer overflow in the fromDhcpListClient function of the Tenda F451 router allows remote attackers to trigger memory corruption via the page argument.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda F451 routers enables remote code execution, posing a severe risk to network integrity.
Vulnerability
The flaw resides in the fromDhcpListClient function within the httpd component and is triggered by a crafted page argument. An attacker with low privileges can remotely execute this stack-based buffer overflow, leading to potential memory corruption.
Business impact
Successful exploitation of this vulnerability can lead to a total compromise of the affected router, potentially allowing an attacker to intercept traffic, pivot into internal network segments, or render the device unusable. Given the CVSS score of 8.8, this represents a high-severity threat that could result in significant operational disruption and data exposure within the affected environment.
Remediation
Immediate Action: Since a specific patch version is currently unknown, administrators should restrict access to the web management interface and monitor for suspicious traffic directed at the /goform/DhcpListClient endpoint.
Proactive Monitoring: Review system logs for signs of unauthorized access or abnormal crash patterns in the httpd service that might indicate exploitation attempts.
Compensating Controls: Deploy a Web Application Firewall or network-level access control list to block unauthorized access to the router's web management interface from untrusted networks.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the referenced GitHub issue.
Analyst recommendation
Given the availability of a public proof-of-concept and the potential for remote code execution, this vulnerability poses a credible and significant risk. Organizations utilizing Tenda F451 hardware should prioritize isolating these devices from the public internet and contact the vendor immediately for firmware update guidance.
More Tenda CVEs
Sources
Originally found and disclosed by Jimi (VulDB User), per the CVE Program record.