CVE-2026-6123: Tenda F451 httpd addressNat fromAddressNat stack-based overflow
Published Apr 12, 2026
·Updated
A vulnerability was found in Tenda F451 1.0.0.7. This affects the function fromAddressNat of the file /goform/addressNat of the component httpd. Performing a manipulation of the argument entrys results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
3 affected components
Tenda F451=1.0.0.7
All of the following
Tenda F451 Firmware=1.0.0.7
Tenda F451
Event History
Apr 12, 2026
CVE Published
via MITRE·08:15 AM
Data Sourced
via MITRE·08:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Jul 20, 58298
Event
via FIRST·03:28 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-6123?
CVE-2026-6123 has a high severity rating of 7.4.
2
How do I fix CVE-2026-6123?
To fix CVE-2026-6123, update the Tenda F451 firmware to the latest version provided by the manufacturer.
3
What types of systems are affected by CVE-2026-6123?
CVE-2026-6123 affects the Tenda F451 device with firmware version 1.0.0.7.
4
What is the nature of the vulnerability in CVE-2026-6123?
CVE-2026-6123 is a stack-based buffer overflow vulnerability that can be exploited remotely.
5
Can CVE-2026-6123 be exploited remotely?
Yes, CVE-2026-6123 can be remotely exploited through manipulation of specific arguments.