Junglewise Threat Intelligence

CVE-2026-6133: Tenda F451 stack overflow in fromSafeUrlFilter

CVE-2026-6133 · Severity: high · CVSS 8.8 · Published 2026-04-12

Technologies: Tenda F451, Tenda F451 Firmware. Vendors: Tenda.

Executive brief

A vulnerability exists in the Tenda F451 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to cause a system crash or potentially take control of the device. This could lead to a complete loss of internet availability or unauthorized access to the local network.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda F451 router running firmware version 1.0.0.7_cn_svn7958. The flaw is located within the 'fromSafeUrlFilter' function in the '/goform/SafeUrlFilter' file. By manipulating the 'page' argument, a remote attacker with low privileges can overflow the stack buffer. This can lead to remote code execution or a denial-of-service (DoS) condition. An exploit for this vulnerability is reportedly available in the public domain.

Affected products

  • Tenda F451 1.0.0.7_cn_svn7958

Timeline

  • 2026-04-12: disclosed: Initial disclosure date
  • 2026-04-12: advisory: CVE-2026-6133 published

References

Related threats