Executive brief
A security vulnerability exists in the Tenda F451 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to crash the router or potentially take full control of the device. This could lead to unauthorized access to network traffic or a complete loss of internet service for the affected environment.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda F451 router (firmware version 1.0.0.7_cn_svn7958). The flaw is located within the 'fromAdvSetWan' function in the '/goform/AdvSetWan' component. The vulnerability is triggered by improper length validation of the 'wanmode' or 'PPPOEPassword' arguments. A remote attacker with low privileges can exploit this by sending a specially crafted request to the web management interface, leading to memory corruption. This can result in arbitrary code execution or a denial of service (DoS). Public exploit code is reportedly available.
Affected products
- Tenda F451 1.0.0.7_cn_svn7958
Timeline
- 2026-04-13: advisory: Initial disclosure date