Executive brief
A security vulnerability has been identified in the Tenda F451 router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to cause a system crash or potentially take control of the device by sending specially crafted data to the router's management interface. This could lead to a complete loss of internet availability or unauthorized access to the local network.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda F451 router firmware version 1.0.0.7. The flaw is located within the 'fromRouteStatic' function in the '/goform/RouteStatic' component. The vulnerability is triggered by improper validation of the 'page' argument, allowing a remote attacker with low privileges to overflow the stack. Successful exploitation can lead to remote code execution (RCE) or a denial of service (DoS) condition. Public exploit code is reportedly available, increasing the risk of exploitation.
Affected products
- Tenda F451 1.0.0.7
Timeline
- 2026-04-10: disclosed: Initial vulnerability disclosure
- 2026-04-10: advisory: NVD advisory published