CVE-2026-5988Disclosure(tenda / f451)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tenda f451 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Performing a manipulation of the argument mit_ssid results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f451
  • f451_firmware

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Exploit: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
f451f451_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 104-0904-10
Signal classification3 categories
Disclosure
133.3%
Exploit
133.3%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-092
Disclosure1Exploit1
2026-04-101
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5988 A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Performing a manipulation of the argu… https://www.cve.org/CVERecord?id=CVE-2026-5988

    Post summary

    The post announces CVE-2026-5988, a vulnerability in Tenda F451 firmware affecting the formWrlsafeset function, providing technical details but no PoC, exploit, or patch information.

    00020166
    57.7K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH SEVERITY: CVE-2026-5988 (CVSS 8.8) Tenda F451 router v1.0.0.7 vulnerable to remote stack-based buffer overflow in formWrlsafeset function. Exploit is PUBLIC. Affected: /goform/AdvSetWrlsafeset Patch immediately! #CVE #Vulnerability #PatchNow https://t.co/BMWh0mI2we

    Post summary

    The tweet alerts to a CVE‑2026‑5988 stack‑buffer-overflow vulnerability in Tenda F451 routers and urges immediate patching, without providing PoC code or active exploitation evidence.

    0000051
    10 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-5988: HIGH] Critical vulnerability in Tenda F451 1.0.0.7! Exploit for remote stack-based buffer overflow attack now public, posing severe cyber threats. Take immediate action.#cve,CVE-2026-5988,#cybersecurity https://cvefind.com/CVE-2026-5988

    Post summary

    The post announces that a remote stack‑based buffer overflow exploit for CVE‑2026‑5988 in the Tenda F451 is publicly available, urging immediate remedial action.

    00000143
    619 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf451---
OStendaf451_firmware1.0.0.7--

Explore more