CVE-2026-6197

8.8

Tenda · F456

A stack-based buffer overflow in the Tenda F456 web interface allows remote attackers to trigger memory corruption and potential code execution via a crafted mit_ssid parameter.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda F456 routers poses a significant risk of remote code execution for authenticated users.

Vulnerability

This vulnerability occurs in the formWrlsafeset function within the /goform/AdvSetWrlsafeset endpoint, where the mit_ssid parameter is processed without adequate length validation. This memory corruption flaw can be triggered by an authenticated user to overwrite the stack, potentially leading to denial of service or remote code execution.

Business impact

Successful exploitation allows an attacker to gain unauthorized control over the affected network device, which may lead to complete compromise of local network traffic or permanent denial of service. Given the high CVSS score of 8.8, this flaw represents a severe threat to infrastructure integrity and data confidentiality.

Remediation

Immediate Action: Contact the vendor for firmware updates, as no official patch is currently identified for this specific version. If no update is available, restrict management interface access to trusted administrative networks only.

Proactive Monitoring: Monitor device logs for unusual POST requests directed at the /goform/AdvSetWrlsafeset endpoint and watch for abnormal system reboots or service crashes.

Compensating Controls: Implement strict network access control lists to prevent unauthorized users from reaching the administrative web interface of the router.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the research write-up by Li Tengzheng.

Analyst recommendation

The presence of a publicly available proof-of-concept significantly lowers the barrier for exploitation. Organizations utilizing Tenda F456 hardware must treat this vulnerability with high urgency, isolating vulnerable devices from the public internet until a vendor-supplied patch is applied.

More Tenda CVEs

Sources

Originally found and disclosed by LtzHuster (VulDB User), per the CVE Program record.