CVE-2026-6135Disclosure(tenda / f451)

LOWCVSS 7.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in Tenda F451 1.0.0.7_cn_svn7958. This issue affects the function fromSetIpBind of the file /goform/SetIpBind. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f451
  • f451_firmware

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-04-13)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
f451f451_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-12: 1Mentions · 2026-04-13: 3Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 204-1204-13
Signal classification3 categories
Disclosure
250.0%
Exploit
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-121
Exploit1
2026-04-133
Disclosure2General1
Full discourse4 posts
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-6135: HIGH] Critical vulnerability found in Tenda F451 1.0.0.7_cn_svn7958 exposing remote attack risk. Exploit available, leading to stack-based buffer overflow via argument manipulation.#cve,CVE-2026-6135,#cybersecurity https://cvefind.com/CVE-2026-6135

    Post summary

    A high‑severity stack‑based buffer overflow was identified in the Tenda F451 router, with an available exploit noted but no patch or PoC detailed.

    0001070
    620 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6135 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6135 #CVE-2026-6135 #CVE #High #CyberSecurity #InfoSec https://t.co/ouv3j0T4aX

    Post summary

    The tweet announces a new high‑severity CVE (CVE‑2026‑6135) with minimal details and just a link to the NVD entry.

    0000027
    125 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6135 A weakness has been identified in Tenda F451 1.0.0.7_cn_svn7958. This issue affects the function fromSetIpBind of the file /goform/SetIpBind. Executing a manipulation o… https://www.cve.org/CVERecord?id=CVE-2026-6135

    Post summary

    The post discloses a weakness in Tenda F451 firmware involving the SetIpBind function but offers no PoC, exploitation details, or patch information.

    0000083
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6135 Stack-Based Buffer Overflow in Tenda F451 1.0.0.7_cn_svn7958 SetIpBind Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6135

    Post summary

    A new vulnerability, CVE-2026-6135, has been disclosed, involving a stack-based buffer overflow in the SetIpBind function of Tenda F451 firmware. Technical details are provided via the Vulmon link.

    0000037
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf451---
OStendaf451_firmware1.0.0.7--

Explore more