Junglewise Threat Intelligence

CVE-2026-6134: Tenda F451 stack buffer overflow in qossetting

CVE-2026-6134 · Severity: high · CVSS 8.8 · Published 2026-04-12

Technologies: Tenda F451, Tenda F451 Firmware. Vendors: Tenda.

Executive brief

A security vulnerability exists in the Tenda F451 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending specially crafted data to the router's management interface. This could lead to unauthorized access to network traffic or a complete disruption of internet services.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda F451 router firmware version 1.0.0.7_cn_svn7958. The flaw is located within the 'fromqossetting' function in the '/goform/qossetting' handler. By manipulating the 'qos' argument, a remote attacker with low privileges can overflow the stack buffer. This can lead to remote code execution (RCE) or a denial of service (DoS) condition. Public exploit code has been released, increasing the risk of active exploitation.

Affected products

  • Tenda F451 1.0.0.7_cn_svn7958

Timeline

  • 2026-04-12: disclosed: Initial disclosure of the vulnerability
  • 2026-04-12: advisory: Vulnerability published on NVD/VulDB

References

Related threats