Executive brief
A vulnerability exists in the Tenda F451 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to cause a system crash or potentially take control of the device. This could lead to a complete loss of internet availability or unauthorized access to the local network.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda F451 router running firmware version 1.0.0.7_cn_svn7958. The flaw is located within the 'fromSafeUrlFilter' function in the '/goform/SafeUrlFilter' file. By manipulating the 'page' argument, a remote attacker with low privileges can overflow the stack buffer. This can lead to remote code execution or a denial-of-service (DoS) condition. An exploit for this vulnerability is reportedly available in the public domain.
Affected products
- Tenda F451 1.0.0.7_cn_svn7958
Timeline
- 2026-04-12: disclosed: Initial disclosure date
- 2026-04-12: advisory: CVE-2026-6133 published