CVE-2026-6120

8.8

Tenda · F451

A stack-based buffer overflow in the fromDhcpListClient function of the Tenda F451 router allows remote attackers to trigger memory corruption via the page argument.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda F451 routers enables remote code execution, posing a severe risk to network integrity.

Vulnerability

The flaw resides in the fromDhcpListClient function within the httpd component and is triggered by a crafted page argument. An attacker with low privileges can remotely execute this stack-based buffer overflow, leading to potential memory corruption.

Business impact

Successful exploitation of this vulnerability can lead to a total compromise of the affected router, potentially allowing an attacker to intercept traffic, pivot into internal network segments, or render the device unusable. Given the CVSS score of 8.8, this represents a high-severity threat that could result in significant operational disruption and data exposure within the affected environment.

Remediation

Immediate Action: Since a specific patch version is currently unknown, administrators should restrict access to the web management interface and monitor for suspicious traffic directed at the /goform/DhcpListClient endpoint.

Proactive Monitoring: Review system logs for signs of unauthorized access or abnormal crash patterns in the httpd service that might indicate exploitation attempts.

Compensating Controls: Deploy a Web Application Firewall or network-level access control list to block unauthorized access to the router's web management interface from untrusted networks.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the referenced GitHub issue.

Analyst recommendation

Given the availability of a public proof-of-concept and the potential for remote code execution, this vulnerability poses a credible and significant risk. Organizations utilizing Tenda F451 hardware should prioritize isolating these devices from the public internet and contact the vendor immediately for firmware update guidance.

More Tenda CVEs

Sources

Originally found and disclosed by Jimi (VulDB User), per the CVE Program record.