Two high-severity vulnerabilities, CVE-2026-6122 and CVE-2026-6136, were disclosed for Tenda F451 routers, both affecting firmware 1.0.0.7 and enabling remote stack-based buffer overflow attacks through the device's httpd web interface. The flaws reside in the /goform/L7Prot and /goform/L7Im endpoints, specifically in the frmL7ProtForm and frmL7ImForm functions, where improper handling of the page argument can corrupt stack memory.
Both CVEs are mapped to CWE-119 and CWE-121, and the disclosures indicate that public exploit details are already available, raising the risk of near-term exploitation against exposed devices. One advisory notes the issue requires only low privileges for exploitation, and both entries describe the attack path as remote, making internet-accessible or poorly segmented Tenda F451 deployments a likely target for abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A second CVE entry was published for a stack-based buffer overflow in the frmL7ImForm function of /goform/L7Im on Tenda F451 firmware 1.0.0.7_cn_svn7958. The vulnerability is remotely exploitable through the page argument, and public exploit disclosure was also noted.
A CVE entry was published for a stack-based buffer overflow in the frmL7ProtForm function of /goform/L7Prot in the Tenda F451 httpd component affecting version 1.0.0.7. The flaw is remotely exploitable via manipulation of the page argument, and the entry notes that a public exploit had already been disclosed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.