Junglewise Threat Intelligence

CVE-2026-6121: Tenda F451 stack overflow in WrlclientSet

CVE-2026-6121 · Severity: high · CVSS 8.8 · Published 2026-04-12

Technologies: Tenda F451, Tenda F451 Firmware. Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda F451 wireless router. This device is commonly used to provide internet connectivity and local networking for homes and small offices. An attacker could exploit this flaw to crash the router or potentially take full control of the device, which could lead to the interception of network traffic or unauthorized access to the local network.

Technical details

A stack-based buffer overflow vulnerability exists in the httpd component of Tenda F451 firmware version 1.0.0.7. The flaw is located within the WrlclientSet function in the /goform/WrlclientSet handler. By manipulating the 'GO' argument in a crafted HTTP request, a remote attacker with low privileges can trigger the overflow. This can lead to arbitrary code execution or a crash of the web service (Denial of Service). Public exploit code is reportedly available, increasing the risk of exploitation.

Affected products

  • Tenda F451 firmware 1.0.0.7

Timeline

  • 2026-04-12: disclosed: Initial vulnerability report published

References

Related threats