Junglewise Threat Intelligence

CVE-2026-11556: Tenda F451 OS command injection in formWriteFacMac

CVE-2026-11556 · Severity: high · CVSS 8.8 · Published 2026-06-08

Technologies: Tenda F451. Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda F451 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to take complete control of the router by sending a specially crafted request to its web management interface. This could allow an unauthorized user to intercept network traffic, disrupt internet service, or use the compromised device as a foothold to attack other devices on the local network.

Technical details

An OS command injection vulnerability exists in the Tenda F451 router (firmware versions V1.0.0.7 and V1.0.0.9) within the 'formWriteFacMac' function of the Web Management Interface. The vulnerability is located in the '/goform/WriteFacMac' endpoint, where the 'mac' parameter is processed without adequate sanitization. The user-supplied input is directly concatenated into a system command string via 'doSystemCmd', allowing an attacker to use shell metacharacters (e.g., ';', '&', '|') to execute arbitrary commands. Successful exploitation requires the attacker to be able to reach the web interface and typically requires low-level authentication, resulting in full Remote Code Execution (RCE) with root privileges. A public exploit (PoC) is available.

Affected products

  • Tenda F451 1.0.0.7, 1.0.0.9

Timeline

  • 2026-06-08: disclosed: Initial disclosure and NVD publication
  • 2026-06-08: advisory

References

Related threats