Junglewise Threat Intelligence

CVE-2026-5989: Tenda F451 stack-based buffer overflow in RouteStatic

CVE-2026-5989 · Severity: high · CVSS 8.8 · Published 2026-04-10

Technologies: Tenda F451, Tenda F451 Firmware. Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda F451 router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to cause a system crash or potentially take control of the device by sending specially crafted data to the router's management interface. This could lead to a complete loss of internet availability or unauthorized access to the local network.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda F451 router firmware version 1.0.0.7. The flaw is located within the 'fromRouteStatic' function in the '/goform/RouteStatic' component. The vulnerability is triggered by improper validation of the 'page' argument, allowing a remote attacker with low privileges to overflow the stack. Successful exploitation can lead to remote code execution (RCE) or a denial of service (DoS) condition. Public exploit code is reportedly available, increasing the risk of exploitation.

Affected products

  • Tenda F451 1.0.0.7

Timeline

  • 2026-04-10: disclosed: Initial vulnerability disclosure
  • 2026-04-10: advisory: NVD advisory published

References

Related threats