CVE-2026-5989: Tenda F451 RouteStatic fromRouteStatic stack-based overflow
A flaw has been found in Tenda F451 1.0.0.7. Affected is the function fromRouteStatic of the file /goform/RouteStatic. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5989?
CVE-2026-5989 is classified as a critical vulnerability due to its potential for remote exploitation and stack-based buffer overflow.
How do I fix CVE-2026-5989?
To fix CVE-2026-5989, update the Tenda F451 router to the latest firmware version that addresses this vulnerability.
What systems are affected by CVE-2026-5989?
CVE-2026-5989 specifically affects the Tenda F451 router running version 1.0.0.7.
What kind of attack can exploit CVE-2026-5989?
An attacker can exploit CVE-2026-5989 by manipulating the argument page in the fromRouteStatic function to execute a stack-based buffer overflow.
Is CVE-2026-5989 exploitable remotely?
Yes, CVE-2026-5989 is exploitable remotely, allowing attackers to potentially compromise the affected router from outside the local network.