CVE-2026-11556: Tenda F451 Web Management WriteFacMac formWriteFacMac os command injection

Published Jun 8, 2026
·
Updated

A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

Affected Software

1 affected component
Tenda F451=1.0.0.7, =1.0.0.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable remote/WAN access to the web management interface. If disabling is not possible, restrict web management to the local LAN and/or specific trusted management IP addresses.

    Tenda F451 Web Management Interface remote_web_management = disabled or restricted to trusted IPs/LAN
  2. Configuration

    If the device supports disabling specific management functions or endpoints, disable the /goform/WriteFacMac (formWriteFacMac) functionality or any factory-MAC write feature to prevent remote invocation.

    Tenda F451 Web Management Interface /goform/WriteFacMac (formWriteFacMac) endpoint = disabled or blocked if possible
  3. Compensating control

    At the network perimeter or on an inline WAF, block or filter HTTP(S) requests targeting the path /goform/WriteFacMac and/or block the router's web management ports from untrusted networks. Restrict access to the management interface to a trusted management network.

  4. Operational

    Monitor device and network logs for requests to /goform/WriteFacMac and signs of command injection against formWriteFacMac. Isolate any compromised or suspicious devices and apply vendor-supplied updates or patches as soon as they are made available.

Event History

Jun 8, 2026
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-11556?

The severity of CVE-2026-11556 is high with a score of 8.8.

2

How does CVE-2026-11556 impact users?

CVE-2026-11556 allows for OS command injection through the formWriteFacMac function in the Tenda F451 web management interface.

3

How can I mitigate CVE-2026-11556?

To mitigate CVE-2026-11556, ensure you're using the most recent firmware for the Tenda F451 that addresses this vulnerability.

4

What versions of Tenda F451 are affected by CVE-2026-11556?

CVE-2026-11556 affects Tenda F451 versions 1.0.0.7 and 1.0.0.9.

5

Is remote exploitation possible with CVE-2026-11556?

Yes, CVE-2026-11556 allows for remote exploitation of the OS command injection vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203