Tenda F451 Router Hit with High-Severity Buffer Overflow

Tenda F451 Router Hit with High-Severity Buffer Overflow

The National Vulnerability Database (NVD) has spotlighted a critical stack-based buffer overflow vulnerability, CVE-2026-6122, impacting the Tenda F451 router, specifically version 1.0.0.7. This bug resides within the frmL7ProtForm function of the /goform/L7Prot component, tied to the httpd service.

Manipulation of the page argument can lead to a stack-based buffer overflow, a classic exploit vector that often enables remote code execution. With a CVSS score of 8.8 (HIGH), this isn’t some theoretical flaw; the NVD notes that an exploit has already been publicly disclosed, meaning it’s likely being actively weaponized in the wild. This makes it a prime target for opportunistic attackers looking to gain a foothold into vulnerable networks, often a precursor to more sophisticated attacks.

While the NVD didn’t specify affected products beyond the Tenda F451 1.0.0.7, it’s a stark reminder that consumer-grade network gear often becomes a soft underbelly for perimeter defenses. These devices, often deployed with default configurations and rarely patched, are low-hanging fruit for attackers.

Indicators of Compromise

IDTypeIndicator
CVE-2026-6122 Buffer Overflow Tenda F451 version 1.0.0.7
CVE-2026-6122 Buffer Overflow CWE-121: Stack-based Buffer Overflow
CVE-2026-6122 Buffer Overflow Vulnerable component: httpd
CVE-2026-6122 Buffer Overflow Vulnerable file: /goform/L7Prot
CVE-2026-6122 Buffer Overflow Vulnerable function: frmL7ProtForm with argument 'page'
🔎
Turn this CVE into SIEM detection coverage Generate detection rules for Splunk, Sentinel, QRadar & Elastic — straight from this vulnerability. Use /detect in the Intel Bot.
Open Intel Bot →

Related Posts

Critical RCE Flaw Hits NuGet Gallery Backend

CVE-2026-39399 — NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within...

vulnerabilityCVEcriticalhigh-severityremote-code-executioncwe-20cwe-22
/CRITICAL /⚑ 4 IOCs

BoidCMS LFI to RCE: A Critical Template Flaw

CVE-2026-39387 — BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are...

vulnerabilityCVEhigh-severityremote-code-executioncwe-98
/HIGH /⚑ 4 IOCs

Nanobot AI: WebSocket Hijack Puts WhatsApp Sessions at Risk

CVE-2026-35589 — nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server...

vulnerabilityCVEhigh-severitycwe-1385
/HIGH /⚑ 5 IOCs