Executive brief
A vulnerability exists in the Tenda F451 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending specially crafted data to the router's management interface. This could lead to a complete loss of internet service or unauthorized access to the network.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda F451 router running firmware version 1.0.0.7. The flaw is located within the 'fromDhcpListClient' function in the '/goform/DhcpListClient' file of the 'httpd' component. The vulnerability is triggered by improper validation of the 'page' argument, allowing a remote attacker with low privileges to overflow the stack. Successful exploitation can lead to remote code execution (RCE) or a denial of service (DoS) condition. A public exploit is reportedly available.
Affected products
- Tenda F451 1.0.0.7
Timeline
- 2026-04-12: advisory: Initial disclosure by VulDB/NVD