Executive brief
A security vulnerability exists in the Tenda FH451 wireless router, a device used to provide internet connectivity in homes and small offices. By sending a specially crafted web request to the router, an attacker can cause the device to crash or become unresponsive. This results in a denial of service, disrupting internet access for all connected users until the device is manually restarted.
Technical details
A stack-based buffer overflow exists in the Tenda FH451 V1.0.0.9 router within the 'fromDhcpListClient' CGI handler. The vulnerability is located in the 'fromDhcpListClient' function, where the 'page' HTTP parameter is retrieved via 'websGetVar' and subsequently passed to 'sprintf' without length validation. Specifically, the input is copied into a fixed-size stack buffer (acStack_120) to construct a URL string. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request with an overly long 'page' parameter, leading to a process crash or device instability (Denial of Service).
Affected products
- Tenda FH451 V1.0.0.9
Timeline
- 2026-03-14: other: CVE request submitted to MITRE
- 2026-06-05: disclosed: Public disclosure and NVD publication