CVE-2026-6122

8.8

Tenda · F451

The Tenda F451 router is vulnerable to a stack-based buffer overflow in the httpd component, allowing remote attackers to trigger memory corruption via the page argument in /goform/L7Prot.

Executive summary

A critical stack-based buffer overflow vulnerability in the Tenda F451 router enables remote code execution and requires immediate attention.

Vulnerability

The vulnerability exists within the frmL7ProtForm function of the httpd component. An attacker with low-level privileges can trigger a stack-based buffer overflow by manipulating the page argument, leading to potential memory corruption.

Business impact

This vulnerability carries a CVSS score of 8.8, indicating a high severity risk. Successful exploitation could allow a remote attacker to crash the affected device, potentially causing a denial of service, or execute arbitrary code, leading to complete compromise of the network gateway and unauthorized access to internal traffic.

Remediation

Immediate Action: Since a specific patch is currently unknown, administrators should restrict access to the web management interface, ensuring it is not exposed to the public internet.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/L7Prot endpoint and review system logs for signs of service crashes or unauthorized configuration changes.

Compensating Controls: Implement a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) rule to filter and block malformed requests containing excessive data in the page parameter.

Exploitation status

Public Exploit Available: Yes, a published PoC exists, attributed to the research write-up at the Jimi-Lab GitHub repository.

Analyst recommendation

Given the high CVSS score and the existence of a public proof-of-concept, the risk to Tenda F451 users is significant. Administrators must isolate the device management interface from external access immediately and monitor for any vendor-released firmware updates to address the underlying memory corruption flaw.

More Tenda CVEs

Sources

Originally found and disclosed by Jxm666 (VulDB User), per the CVE Program record.