Junglewise Threat Intelligence

CVE-2026-5991: Tenda F451 stack overflow in formWrlExtraSet

CVE-2026-5991 · Severity: high · CVSS 8.8 · Published 2026-04-10

Technologies: Tenda F451, Tenda F451 Firmware. Vendors: Tenda.

Executive brief

A vulnerability exists in the Tenda F451 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to cause a system crash or potentially take full control of the router. This could lead to unauthorized access to network traffic, service outages, or the use of the device as a foothold for further attacks on the internal network.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda F451 router running firmware version 1.0.0.7. The flaw is located within the 'formWrlExtraSet' function in the '/goform/WrlExtraSet' component. The vulnerability is triggered by improper validation of the 'GO' argument, which allows an attacker to overwrite the stack. While the attack can be launched remotely, it requires low-level authentication (PR:L). Successful exploitation can lead to complete compromise of the device (Confidentiality, Integrity, and Availability impact). A public exploit is reportedly available.

Affected products

  • Tenda F451 1.0.0.7

Timeline

  • 2026-04-10: disclosed: Initial publication date

References

Related threats