CVE-2026-6630

8.8

Tenda · F451

A buffer overflow vulnerability in the Tenda F451 web interface allows remote attackers to trigger memory corruption via the dips argument in the fromGstDhcpSetSer function.

Executive summary

A critical memory corruption vulnerability in Tenda F451 routers enables remote attackers to trigger a buffer overflow, posing a significant risk to device integrity and network security.

Vulnerability

This issue is a buffer overflow (CWE-120) triggered by improper memory handling within the fromGstDhcpSetSer function of the httpd service. While the CVSS vector indicates low privileges are required, the vulnerability is remotely exploitable and leads to total compromise of the affected component.

Business impact

The exploitation of this buffer overflow allows for arbitrary code execution or a denial of service, potentially resulting in full device takeover. Given the CVSS score of 8.8, this vulnerability presents a high risk to organizational infrastructure by allowing attackers to intercept traffic or gain unauthorized access to the internal network.

Remediation

Immediate Action: Contact Tenda support or monitor the official vendor portal for firmware updates, as no official patch is currently identified for this specific version.

Proactive Monitoring: Inspect network logs for unusual traffic directed at the /goform/GstDhcpSetSer endpoint and monitor for unexpected router reboots or service instability.

Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses and employ a WAF or firewall rule to filter malicious payloads from incoming HTTP requests.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up at the referenced GitHub repository.

Analyst recommendation

Due to the availability of a public proof-of-concept and the high severity of the memory corruption flaw, immediate attention is required. Administrators should isolate the affected Tenda F451 devices from the public internet until a vendor-supplied firmware update is verified and applied.

More Tenda CVEs

Sources

Originally found and disclosed by Jxm666 (VulDB User), per the CVE Program record.