CVE-2026-6630Active Exploitation

LOWCVSS 7.4 · HIGH

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was found in Tenda F451 1.0.0.7_cn_svn7958. This issue affects the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. Performing a manipulation of the argument dips results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-20: 3Active Exploitation · 2026-04-20: 1Technical Details · 2026-04-20: 104-20
Signal classification3 categories
Active Exploitation
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting Tenda F451 (CVE-2026-6630) https://vuldb.com/vuln/358264/cti

    Post summary

    The post reports increased attacker activity targeting Tenda F451 CVE-2026-6630, indicating the vulnerability is being actively exploited in the wild, though no exploit code, patch, or detailed technical data is provided.

    0001056
    2.1K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6630 A vulnerability was found in Tenda F451 1.0.0.7_cn_svn7958. This issue affects the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. … https://www.cve.org/CVERecord?id=CVE-2026-6630

    Post summary

    The statement merely notes that CVE‑2026‑6630 affects a specific Tenda firmware component, offering no additional exploitation or mitigation details.

    0000060
    57.2K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-6630 A vulnerability was found in Tenda F451 1.0.0.7_cn_svn7958. This issue affects the function fromGstDhcpSetSer of the fi… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-6630 #Tenda #CyberSecurity #InfoSec

    Post summary

    A high‑severity vulnerability (CVE‑2026‑6630) affecting the Tenda F451's fromGstDhcpSetSer function was disclosed, with a CVSS score of 8.8 and further analysis linked.

    000003
    124 followersView on X

Explore more