CVE-2026-5991Disclosure(tenda / f451)

LOWCVSS 7.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch tenda f451 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Tenda F451 1.0.0.7. Affected by this issue is the function formWrlExtraSet of the file /goform/WrlExtraSet. The manipulation of the argument GO results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f451
  • f451_firmware

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
f451f451_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-10: 3Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-10: 304-10
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • NerdieNews@NewsNerdie
    Patch

    A stack-based buffer overflow in Tenda F451's formWrlExtraSet function (CVE-2026-5991) lets attackers execute arbitrary code, compromising network security. Patch now to prevent exploitation. #NerdieNews #CyberSecurity #InfoSec #Ransomware #Malware #WordPress

    Post summary

    The post highlights a stack-based buffer overflow in Tenda F451 (CVE-2026-5991) that allows arbitrary code execution and urges immediate patching.

    0001059
    54 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5991 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5991 #CVE-2026-5991 #CVE #High #CyberSecurity #InfoSec https://t.co/taiinA3Atl

    Post summary

    A new CVE-2026-5991 is announced with a severity score of 8.8 and high risk, but no detailed exploit or mitigation information is provided.

    0000043
    123 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5991: HIGH] Tenda F451 1.0.0.7 device has a critical vulnerability in /goform/WrlExtraSet function allowing remote attackers to execute a stack-based buffer overflow attack.#cve,CVE-2026-5991,#cybersecurity https://cvefind.com/CVE-2026-5991

    Post summary

    Disclosed a high‑severity stack‑based buffer overflow vulnerability in the Tenda F451 1.0.0.7 firmware's /goform/WrlExtraSet endpoint, enabling remote attackers to execute code.

    0000049
    619 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf451---
OStendaf451_firmware1.0.0.7--

Explore more