PT-2026-31831 · Tenda · Tenda Fh451
Jimi
·
Published
2026-03-30
·
Updated
2026-04-10
·
CVE-2026-5991
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda F451 version 1.0.0.7
Description
A stack-based buffer overflow exists in the
formWrlExtraSet function located in the /goform/WrlExtraSet file of the Tenda F451 device. The GO argument can be manipulated to trigger this overflow, potentially allowing for remote code execution. The exploit has been publicly released.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the
/goform/WrlExtraSet file.Exploit
Fix
Buffer Overflow
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Fh451