Executive brief
A security vulnerability exists in the Tenda F451 router, a device used for home and small office networking. An attacker can exploit this flaw to cause a system crash or potentially take control of the device by sending specially crafted data to the router's management interface. This could lead to unauthorized access to the network, interception of traffic, or a complete loss of internet connectivity.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda F451 router firmware version 1.0.0.7_cn_svn7958. The flaw is located within the 'frmL7ImForm' function in the '/goform/L7Im' component, where improper validation of the 'page' argument allows for memory corruption. An attacker with network access and low-level privileges can exploit this by sending a malicious request to the web management interface. Successful exploitation can lead to remote code execution (RCE) or a denial-of-service (DoS) condition. Public exploit code has been disclosed, increasing the risk of active exploitation.
Affected products
- Tenda F451 1.0.0.7_cn_svn7958
Timeline
- 2026-04-13: disclosed: Vulnerability disclosed and CVE assigned