Junglewise Threat Intelligence

CVE-2026-6123: Tenda F451 stack-based buffer overflow in fromAddressNat

CVE-2026-6123 · Severity: high · CVSS 8.8 · Published 2026-04-12

Technologies: Tenda F451, Tenda F451 Firmware. Vendors: Tenda.

Executive brief

A security vulnerability exists in the Tenda F451 wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can exploit this flaw to cause a system crash or potentially take full control of the router. This could lead to unauthorized access to network traffic, service outages, or a foothold for further attacks on connected devices.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda F451 router (firmware version 1.0.0.7) within the 'httpd' component. The flaw is located in the 'fromAddressNat' function in the '/goform/addressNat' file, where improper validation of the 'entrys' argument allows for memory corruption. An attacker with low-level privileges can exploit this over the network to achieve remote code execution or cause a denial of service (DoS). Public exploit code is reportedly available, increasing the risk of exploitation. No official patch is mentioned in the advisory, so users should ensure management interfaces are not exposed to the public internet.

Affected products

  • Tenda F451 1.0.0.7

Timeline

  • 2026-04-12: disclosed: Initial disclosure of the vulnerability
  • 2026-04-12: advisory: NVD publication date

References

Related threats