Two high-severity vulnerabilities have been disclosed in Tenda routers, both enabling remote stack-based buffer overflows through exposed /goform/ endpoints. CVE-2026-4551 affects the Tenda F453 running version 1.0.0.3, where the fromSafeClientFilter function in the /goform/SafeClientFilter handler can be exploited by manipulating the menufacturer/Go argument. CVE-2026-5990 affects the Tenda F451 running version 1.0.0.7, where the fromSafeEmailFilter function in the /goform/SafeEmailFilter component can be triggered via the page argument.
Both flaws are classified under CWE-119 and CWE-121 and are described as remotely exploitable with public exploit information available, raising the risk of active abuse against exposed devices. The CVE records assign high impact across confidentiality, integrity, and availability in published CVSS scoring, indicating that successful exploitation could give attackers a powerful path to compromise vulnerable edge networking equipment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A new CVE entry disclosed a remotely exploitable stack-based buffer overflow in Tenda F451 firmware version 1.0.0.7_cn_svn7958. The flaw affects the fromSafeUrlFilter function in the /goform/SafeUrlFilter endpoint, and the record states that a public exploit is available.
A new CVE entry disclosed a remotely exploitable stack-based buffer overflow in Tenda F451 firmware version 1.0.0.7. The flaw affects the fromSafeMacFilter function in the /goform/SafeMacFilter endpoint, and public exploit disclosure was noted.
A new CVE entry disclosed a remotely exploitable stack-based buffer overflow in Tenda F451 firmware version 1.0.0.7. The flaw affects the fromAddressNat function in the /goform/addressNat endpoint, and public exploit availability was noted.
A new CVE entry disclosed a remotely exploitable stack-based buffer overflow in Tenda F451 firmware version 1.0.0.7. The flaw affects the fromSafeEmailFilter function in the /goform/SafeEmailFilter component, and the exploit was reported as publicly disclosed.
A new CVE entry disclosed a remotely exploitable stack-based buffer overflow in Tenda F453 version 1.0.0.3. The flaw affects the fromSafeClientFilter function in the /goform/SafeClientFilter endpoint, and public exploit information was noted as available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.