Executive brief
A security vulnerability has been identified in the Tenda F451 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker could exploit this flaw to crash the router or potentially take full control of the device, leading to unauthorized access to network traffic or service disruptions. This issue is particularly concerning as technical details and exploit methods have been made public.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda F451 router firmware version 1.0.0.7_cn_svn7958. The flaw is located within the 'fromSetIpBind' function in the '/goform/SetIpBind' component. The vulnerability is triggered by improper validation of the 'page' argument, which allows an attacker to overwrite the stack. While the attack requires low-level authentication (PR:L), it can be executed remotely over the network. Successful exploitation can lead to arbitrary code execution or a complete system crash (Denial of Service). Public exploit code is reportedly available.
Affected products
- Tenda F451 1.0.0.7_cn_svn7958
Timeline
- 2026-04-13: advisory: Initial disclosure date