Executive brief
A vulnerability exists in the Tenda F451 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker could exploit this flaw to crash the router or potentially take full control of the device. This could lead to unauthorized access to network traffic, service disruptions, or a foothold for further attacks on the local network.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in the Tenda F451 router firmware version 1.0.0.7. The flaw is located within the 'fromP2pListFilter' function in the '/goform/P2pListFilter' file. The vulnerability is triggered by improper validation of the 'page' argument, allowing an attacker to overwrite the stack. Exploitation requires network reachability and low-level authentication (PR:L). Successful exploitation can lead to remote code execution (RCE) or a complete system crash. A public exploit has been disclosed.
Affected products
- Tenda F451 1.0.0.7
Timeline
- 2026-04-10: advisory: Initial disclosure date