Executive brief
A security vulnerability exists in the Tenda F451 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending specially crafted data to the router's management interface. This could lead to unauthorized access to network traffic or a complete disruption of internet services.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda F451 router firmware version 1.0.0.7_cn_svn7958. The flaw is located within the 'fromqossetting' function in the '/goform/qossetting' handler. By manipulating the 'qos' argument, a remote attacker with low privileges can overflow the stack buffer. This can lead to remote code execution (RCE) or a denial of service (DoS) condition. Public exploit code has been released, increasing the risk of active exploitation.
Affected products
- Tenda F451 1.0.0.7_cn_svn7958
Timeline
- 2026-04-12: disclosed: Initial disclosure of the vulnerability
- 2026-04-12: advisory: Vulnerability published on NVD/VulDB