Junglewise Threat Intelligence

CVE-2026-36786: Tenda FH451 stack overflow in fromDhcpListClient

CVE-2026-36786 · Severity: info · CVSS 7.5 · Published 2026-06-08

Vendors: Tenda.

Executive brief

The Tenda FH451 wireless router contains a security flaw in its web management interface. An attacker can send a specially crafted web request to the device to cause it to crash or become unresponsive. This results in a denial of service, disrupting internet connectivity for users relying on the router.

Technical details

A stack-based buffer overflow exists in the Tenda FH451 V1.0.0.9 firmware within the 'fromDhcpListClient' CGI handler. The vulnerability is located in the handling of the 'list1' HTTP parameter, where user-supplied input is copied into a fixed-size stack buffer using 'strcpy' without proper bounds checking. An unauthenticated attacker can trigger this overflow by sending a crafted HTTP request with an excessively long string in the 'list1' parameter. This leads to a process crash or device instability, resulting in a Denial of Service (DoS).

Affected products

  • Tenda FH451 V1.0.0.9

Timeline

  • 2026-03-14: other: CVE request submitted to MITRE
  • 2026-06-06: disclosed: Public disclosure
  • 2026-06-08: advisory: NVD publication date

References

Related threats