CVE-2026-6135

8.8

Tenda · F451

A stack-based buffer overflow in the Tenda F451 SetIpBind function allows remote attackers to trigger memory corruption via the page argument.

Executive summary

A remote stack-based buffer overflow in Tenda F451 allows for potential system compromise, requiring immediate attention.

Vulnerability

This vulnerability is a stack-based buffer overflow (CWE-121) located in the SetIpBind function within the /goform/SetIpBind endpoint. The flaw can be triggered remotely by manipulating the page argument, requiring low privileges to execute.

Business impact

The vulnerability poses a severe risk to business operations, as successful exploitation results in memory corruption that may lead to arbitrary code execution or a complete denial of service. With a CVSS score of 8.8, this flaw is considered high severity, potentially leading to unauthorized system access or the total loss of device availability.

Remediation

Immediate Action: Contact Tenda for the latest firmware updates or security patches for the F451 device, as there is currently no publicly confirmed patch available.

Proactive Monitoring: Review device access logs for unusual traffic patterns directed toward the /goform/SetIpBind endpoint.

Compensating Controls: Implement network segmentation to restrict access to the device management interface and deploy a Web Application Firewall to filter malicious input payloads targeting the affected parameter.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists and is documented in the referenced security research.

Analyst recommendation

Given the high CVSS score and the existence of a public proof-of-concept, users should prioritize securing these devices immediately. If a firmware update from Tenda is not available, isolate the affected hardware from the public internet to prevent remote exploitation.

More Tenda CVEs

Sources

Originally found and disclosed by Jxm666 (VulDB User), per the CVE Program record.