CVE-2026-6124
8.8Tenda · F451
A stack-based buffer overflow in the Tenda F451 router allows remote attackers to trigger memory corruption via the page/menufacturer argument in the fromSafeMacFilter function.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda F451 routers enables remote attackers to execute arbitrary code or cause a system crash.
Vulnerability
The vulnerability exists in the fromSafeMacFilter function within the httpd component. An attacker can trigger a stack-based buffer overflow by manipulating the page/menufacturer argument, which is accessible to authenticated users.
Business impact
The exploitation of this memory corruption vulnerability can result in full system compromise, including unauthorized access to network traffic or persistent denial of service. With a CVSS score of 8.8, this flaw represents a significant risk to the integrity and availability of the affected network infrastructure. Organizations failing to secure these devices risk lateral movement by attackers into internal network segments.
Remediation
Immediate Action: Contact the vendor for firmware updates or, if no patch is available, isolate the device from the public internet immediately.
Proactive Monitoring: Review web server logs for irregular input strings directed at the /goform/SafeMacFilter endpoint and monitor for unexpected device reboots.
Compensating Controls: Implement strict firewall rules to restrict access to the web management interface of the Tenda F451 to trusted management IP addresses only.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the referenced GitHub repository.
Analyst recommendation
Given the high CVSS severity and the existence of a public proof-of-concept, users must treat this vulnerability with extreme urgency. Administrators should restrict management access to the device immediately and prioritize firmware updates as soon as they are released by Tenda to mitigate the risk of remote code execution.
More Tenda CVEs
Sources
Originally found and disclosed by Jxm666 (VulDB User), per the CVE Program record.