CVE-2026-11556: Tenda F451 Web Management WriteFacMac formWriteFacMac os command injection
A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable remote/WAN access to the web management interface. If disabling is not possible, restrict web management to the local LAN and/or specific trusted management IP addresses.
Tenda F451 Web Management Interface remote_web_management = disabled or restricted to trusted IPs/LAN - Configuration
If the device supports disabling specific management functions or endpoints, disable the /goform/WriteFacMac (formWriteFacMac) functionality or any factory-MAC write feature to prevent remote invocation.
Tenda F451 Web Management Interface /goform/WriteFacMac (formWriteFacMac) endpoint = disabled or blocked if possible - Compensating control
At the network perimeter or on an inline WAF, block or filter HTTP(S) requests targeting the path /goform/WriteFacMac and/or block the router's web management ports from untrusted networks. Restrict access to the management interface to a trusted management network.
- Operational
Monitor device and network logs for requests to /goform/WriteFacMac and signs of command injection against formWriteFacMac. Isolate any compromised or suspicious devices and apply vendor-supplied updates or patches as soon as they are made available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11556?
The severity of CVE-2026-11556 is high with a score of 8.8.
How does CVE-2026-11556 impact users?
CVE-2026-11556 allows for OS command injection through the formWriteFacMac function in the Tenda F451 web management interface.
How can I mitigate CVE-2026-11556?
To mitigate CVE-2026-11556, ensure you're using the most recent firmware for the Tenda F451 that addresses this vulnerability.
What versions of Tenda F451 are affected by CVE-2026-11556?
CVE-2026-11556 affects Tenda F451 versions 1.0.0.7 and 1.0.0.9.
Is remote exploitation possible with CVE-2026-11556?
Yes, CVE-2026-11556 allows for remote exploitation of the OS command injection vulnerability.