Executive brief
A vulnerability exists in the Tenda F451 wireless router that could allow an attacker to disrupt the device or take control of it. By sending a specially crafted request to the router's email filtering settings, an attacker can cause a system crash or execute unauthorized commands. This could lead to a total loss of internet connectivity or the compromise of data passing through the network.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda F451 router, firmware version 1.0.0.7. The flaw is located within the 'fromSafeEmailFilter' function in the '/goform/SafeEmailFilter' component. An attacker can trigger the overflow by manipulating the 'page' argument in a remote request. Successful exploitation requires low-level authentication (PR:L) but can lead to full system compromise, including arbitrary code execution or a denial-of-service (DoS) condition. Public exploit code is reportedly available.
Affected products
- Tenda F451 1.0.0.7
Timeline
- 2026-04-10: disclosed: Initial publication date