CVE-2026-6123

8.8

Tenda · F451

A stack-based buffer overflow in the Tenda F451 httpd component allows remote attackers to trigger memory corruption via the fromAddressNat function.

Executive summary

A critical stack-based buffer overflow vulnerability in the Tenda F451 router allows remote attackers to achieve arbitrary memory corruption, posing a severe risk of system compromise.

Vulnerability

This vulnerability is a stack-based buffer overflow occurring within the fromAddressNat function of the httpd component. It is triggered by manipulating the entrys argument, and the CVSS vector indicates that a remote, authenticated attacker can cause memory corruption.

Business impact

Successful exploitation of this buffer overflow could lead to a complete compromise of the affected router, potentially allowing an attacker to gain unauthorized control over network traffic or disrupt critical business communication. With a CVSS score of 8.8, this flaw represents a high risk to infrastructure integrity and data confidentiality, necessitating immediate attention to prevent unauthorized access to the local network.

Remediation

Immediate Action: As no specific patch version is currently listed by the vendor, users should restrict access to the web management interface to trusted internal segments only and monitor for anomalous traffic patterns.

Proactive Monitoring: Security teams should review device access logs for unusual requests directed at the /goform/addressNat endpoint and monitor for unexpected service restarts.

Compensating Controls: Deploying a network-based intrusion detection system or configuring firewall rules to block unauthorized external access to the device management interface can mitigate the risk of remote exploitation.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the research write-up at the Jimi-Lab GitHub repository.

Analyst recommendation

Given the availability of a public proof-of-concept and the high severity of the memory corruption flaw, administrators must treat this as a priority. Immediately isolate the management interface of the affected Tenda F451 devices from public-facing networks and maintain close contact with the vendor for the release of an official firmware security update.

More Tenda CVEs

Sources

Originally found and disclosed by Jxm666 (VulDB User), per the CVE Program record.