Executive brief
A security vulnerability exists in the Tenda F451 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to crash the device or potentially take full control of its operations. This could lead to a complete loss of internet service or unauthorized access to network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda F451 router running firmware version 1.0.0.7. The flaw is located within the 'frmL7ProtForm' function of the '/goform/L7Prot' endpoint in the 'httpd' component. By manipulating the 'page' argument in a crafted HTTP request, a remote attacker with low privileges can trigger the overflow. This can result in a denial-of-service (DoS) condition or arbitrary code execution on the device. Public exploit code has been disclosed.
Affected products
- Tenda F451 1.0.0.7
Timeline
- 2026-04-12: disclosed: Vulnerability disclosed and CVE assigned