CVE-2026-6120: Tenda F451 httpd DhcpListClient fromDhcpListClient stack-based overflow
Published Apr 12, 2026
·Updated
A vulnerability was detected in Tenda F451 1.0.0.7. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.
Affected Software
3 affected components
Tenda F451=1.0.0.7
All of the following
Tenda F451 Firmware=1.0.0.7
Tenda F451
Event History
Apr 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeaknessAffected Software
Jul 20, 58298
Event
via FIRST·06:44 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-6120?
The severity of CVE-2026-6120 is rated as high with a score of 7.4.
2
How do I fix CVE-2026-6120?
To fix CVE-2026-6120, update the Tenda F451 firmware to the latest version provided by the manufacturer.
3
What type of vulnerability is CVE-2026-6120?
CVE-2026-6120 is a stack-based buffer overflow vulnerability.
4
Can CVE-2026-6120 be exploited remotely?
Yes, CVE-2026-6120 can be exploited remotely due to its nature.
5
What software is affected by CVE-2026-6120?
CVE-2026-6120 affects the Tenda F451 version 1.0.0.7 firmware.