CVE-2026-6120Disclosure(tenda / f451)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (5 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in Tenda F451 1.0.0.7. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f451
  • f451_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Exploit: 1 classified signal
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
f451f451_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-04-12: 5PoC Mentioned / Linked · 2026-04-12: 1Technical Details · 2026-04-12: 504-12
Signal classification2 categories
Disclosure
480.0%
Exploit
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6120 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6120 #CVE-2026-6120 #CVE #High #CyberSecurity #InfoSec https://t.co/HYyL9OpDsS

    Post summary

    The tweet simply announces the existence of CVE-2026-6120 and its severity rating, without providing additional exploitation or mitigation details.

    0000042
    125 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6120 A vulnerability was detected in Tenda F451 1.0.0.7. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. The manipulat… https://www.cve.org/CVERecord?id=CVE-2026-6120 ----- Traducción: CVE-2026-6120 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑6120 in a Tenda device, providing a short technical description of the affected function and file, but no evidence of exploits, patches, or active attacks.

    0000031
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6120 A vulnerability was detected in Tenda F451 1.0.0.7. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. The manipulat… https://www.cve.org/CVERecord?id=CVE-2026-6120

    Post summary

    A new vulnerability (CVE-2026-6120) was reported in Tenda F451, affecting the fromDhcpListClient function of httpd, with no evidence of active exploitation or available patch.

    00000183
    57.1K followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-6120: HIGH] Critical vulnerability found in Tenda F451 1.0.0.7: stack-based buffer overflow in httpd component allows remote attacks via manipulated argument. Exploit now public.#cve,CVE-2026-6120,#cybersecurity https://cvefind.com/CVE-2026-6120

    Post summary

    The post discloses CVE‑2026‑6120, highlighting a stack‑based buffer overflow in a Tenda router’s httpd component and noting that an exploit has become public, though no exploit code or patch details are shared.

    0000045
    620 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6120 Stack-Based Buffer Overflow in Tenda F451 1.0.0.7 DhcpListClient Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6120

    Post summary

    The post announces a stack-based buffer overflow vulnerability (CVE-2026-6120) in the Tenda F451 router and links to a vulnerability details page.

    0000047
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf451---
OStendaf451_firmware1.0.0.7--

Explore more