CVE-2026-6123
8.8Tenda · F451
A stack-based buffer overflow in the Tenda F451 httpd component allows remote attackers to trigger memory corruption via the fromAddressNat function.
Executive summary
A critical stack-based buffer overflow vulnerability in the Tenda F451 router allows remote attackers to achieve arbitrary memory corruption, posing a severe risk of system compromise.
Vulnerability
This vulnerability is a stack-based buffer overflow occurring within the fromAddressNat function of the httpd component. It is triggered by manipulating the entrys argument, and the CVSS vector indicates that a remote, authenticated attacker can cause memory corruption.
Business impact
Successful exploitation of this buffer overflow could lead to a complete compromise of the affected router, potentially allowing an attacker to gain unauthorized control over network traffic or disrupt critical business communication. With a CVSS score of 8.8, this flaw represents a high risk to infrastructure integrity and data confidentiality, necessitating immediate attention to prevent unauthorized access to the local network.
Remediation
Immediate Action: As no specific patch version is currently listed by the vendor, users should restrict access to the web management interface to trusted internal segments only and monitor for anomalous traffic patterns.
Proactive Monitoring: Security teams should review device access logs for unusual requests directed at the /goform/addressNat endpoint and monitor for unexpected service restarts.
Compensating Controls: Deploying a network-based intrusion detection system or configuring firewall rules to block unauthorized external access to the device management interface can mitigate the risk of remote exploitation.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the research write-up at the Jimi-Lab GitHub repository.
Analyst recommendation
Given the availability of a public proof-of-concept and the high severity of the memory corruption flaw, administrators must treat this as a priority. Immediately isolate the management interface of the affected Tenda F451 devices from public-facing networks and maintain close contact with the vendor for the release of an official firmware security update.
More Tenda CVEs
Sources
Originally found and disclosed by Jxm666 (VulDB User), per the CVE Program record.
- VDB-356986 | Tenda F451 httpd addressNat fromAddressNat stack-based overflow Vulnerability database entry
- VDB-356986 | CTI Indicators (IOB, IOC, IOA)
- Submit #792873 | Tenda F451_kfw_V1.0.0.7_cn_svn7958 V1.0.0.7 Buffer Overflow Third-party advisory
- Submit #792879 | Tenda F451_kfw_V1.0.0.7_cn_svn7958 V1.0.0.7 Buffer Overflow (Duplicate) Third-party advisory
- Exploit / PoC
- tenda.com.cn