Junglewise Threat Intelligence

CVE-2026-6124: Tenda F451 stack overflow in fromSafeMacFilter

CVE-2026-6124 · Severity: high · CVSS 8.8 · Published 2026-04-12

Technologies: Tenda F451, Tenda F451 Firmware. Vendors: Tenda.

Executive brief

A security vulnerability exists in the Tenda F451 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to crash the router or potentially take full control of the device, which could lead to the interception of network traffic or unauthorized access to the local network. This issue can be triggered remotely, though it typically requires the attacker to have some level of access or credentials for the device.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda F451 router (firmware version 1.0.0.7) within the 'httpd' component. The flaw is located in the 'fromSafeMacFilter' function in the '/goform/SafeMacFilter' file. An attacker can trigger the overflow by manipulating the 'page/menufacturer' argument in a network request. While the attack can be executed remotely, CVSS metrics suggest low privileges (PR:L) are required. Successful exploitation can lead to complete compromise of the device's confidentiality, integrity, and availability. A public exploit has been disclosed.

Affected products

  • Tenda F451 1.0.0.7

Timeline

  • 2026-04-12: disclosed: Initial disclosure of the vulnerability
  • 2026-04-12: advisory: Vulnerability published by VulDB and NVD

References

Related threats