Junglewise Threat Intelligence

CVE-2026-6136: Tenda F451 stack-based buffer overflow in frmL7ImForm

CVE-2026-6136 · Severity: high · CVSS 8.8 · Published 2026-04-13

Technologies: Tenda F451, Tenda F451 Firmware. Vendors: Tenda.

Executive brief

A security vulnerability exists in the Tenda F451 router, a device used for home and small office networking. An attacker can exploit this flaw to cause a system crash or potentially take control of the device by sending specially crafted data to the router's management interface. This could lead to unauthorized access to the network, interception of traffic, or a complete loss of internet connectivity.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda F451 router firmware version 1.0.0.7_cn_svn7958. The flaw is located within the 'frmL7ImForm' function in the '/goform/L7Im' component, where improper validation of the 'page' argument allows for memory corruption. An attacker with network access and low-level privileges can exploit this by sending a malicious request to the web management interface. Successful exploitation can lead to remote code execution (RCE) or a denial-of-service (DoS) condition. Public exploit code has been disclosed, increasing the risk of active exploitation.

Affected products

  • Tenda F451 1.0.0.7_cn_svn7958

Timeline

  • 2026-04-13: disclosed: Vulnerability disclosed and CVE assigned

References

Related threats