CVE-2026-6136

8.8

Tenda · F451

The Tenda F451 router contains a stack-based buffer overflow in the frmL7ImForm function due to improper handling of the page argument, allowing for potential remote code execution.

Executive summary

A critical stack-based buffer overflow vulnerability in the Tenda F451 router allows remote attackers to compromise system integrity via the L7Im form.

Vulnerability

This vulnerability is a stack-based buffer overflow (CWE-121) triggered by manipulating the page argument within the frmL7ImForm function of the /goform/L7Im endpoint. The attack can be initiated remotely by an authenticated user.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high severity risk that could lead to full system compromise. Successful exploitation allows for unauthorized code execution, which may result in a total loss of confidentiality, integrity, and availability of the affected network device.

Remediation

Immediate Action: Contact Tenda support or check the official website for firmware updates addressing this buffer overflow, as no specific patch version is currently identified.

Proactive Monitoring: Monitor network traffic for anomalous requests directed at the /goform/L7Im endpoint and review router logs for signs of unauthorized access or service crashes.

Compensating Controls: Implement strict access control lists on the management interface and place the device behind a firewall to restrict access to the web administration panel from untrusted networks.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up at the referenced GitHub repository.

Analyst recommendation

Given the presence of a public proof-of-concept and the high CVSS score, this vulnerability poses a significant risk to affected environments. Administrators should prioritize restricting network access to the device management interface immediately until a formal vendor patch can be applied.

More Tenda CVEs

Sources

Originally found and disclosed by Jxm666 (VulDB User), per the CVE Program record.