CVE-2026-5991: Tenda F451 WrlExtraSet formWrlExtraSet stack-based overflow
A vulnerability was found in Tenda F451 1.0.0.7. Affected by this issue is the function formWrlExtraSet of the file /goform/WrlExtraSet. The manipulation of the argument GO results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5991?
CVE-2026-5991 is classified as a medium severity vulnerability due to its potential for stack-based buffer overflow.
How do I fix CVE-2026-5991?
To fix CVE-2026-5991, update the Tenda F451 firmware to the latest version provided by the vendor.
What is affected by CVE-2026-5991?
CVE-2026-5991 affects Tenda F451 version 1.0.0.7 specifically.
What type of vulnerability is CVE-2026-5991?
CVE-2026-5991 is a stack-based buffer overflow vulnerability found in the formWrlExtraSet function.
How could an attacker exploit CVE-2026-5991?
An attacker could exploit CVE-2026-5991 by manipulating the GO argument in a request to the /goform/WrlExtraSet file.