CVE-2026-6631
8.8Tenda · F451
A buffer overflow vulnerability exists in the Tenda F451 web interface, allowing remote attackers to potentially execute arbitrary code by manipulating the page argument.
Executive summary
A critical buffer overflow vulnerability in the Tenda F451 router allows remote, authenticated attackers to achieve total system compromise.
Vulnerability
The vulnerability exists within the webExcptypemanFilter function of the httpd component. By sending a crafted request with a manipulated page argument, a remote authenticated attacker can trigger a buffer overflow, leading to memory corruption.
Business impact
Successful exploitation of this vulnerability results in full system compromise, potentially allowing an attacker to gain unauthorized control over the network device. Given the CVSS score of 8.8, this poses a high risk of lateral movement within the network, data interception, or service disruption, which can severely impact business operations and overall network security posture.
Remediation
Immediate Action: Since a specific patch version is not currently available, administrators should restrict access to the web management interface to trusted internal segments only.
Proactive Monitoring: Monitor device logs for unusual traffic patterns or errors originating from the /goform/webExcptypemanFilter endpoint, which may indicate exploitation attempts.
Compensating Controls: Implement network-level access control lists to block unauthorized access to the device management interface.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists as documented in the GitHub issue reported by Jimi-Lab.
Analyst recommendation
The vulnerability represents a significant risk to the integrity and availability of the Tenda F451 router. While a vendor patch is currently not confirmed, organizations must isolate the device management interface from untrusted networks immediately. Security teams should prioritize monitoring for anomalous activity and apply official firmware updates as soon as they are released by the vendor.
More Tenda CVEs
Sources
Originally found and disclosed by jimi666 (VulDB User), per the CVE Program record.