CVE-2026-6134: Tenda F451 qossetting fromqossetting stack-based overflow
A security flaw has been discovered in Tenda F451 1.0.0.7cnsvn7958. This vulnerability affects the function fromqossetting of the file /goform/qossetting. Performing a manipulation of the argument qos results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenda F451to a version that resolves this vulnerability.Fixed in 1.0.0.7_cn_svn7958 - Compensating control
Since the vulnerability is remotely exploitable via /goform/qossetting (function fromqossetting), restrict network access to the router’s web management/API endpoint to only trusted sources (e.g., block at firewall/ACL and allow only required IPs).
- Operational
If this device is exposed and the exploit is publicly available, check for signs of exploitation and reset/reconfigure any impacted settings; monitor logs around requests to /goform/qossetting (fromqossetting) after mitigation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6134?
CVE-2026-6134 has a severity rating of high, with a score of 7.4.
What type of vulnerability is described in CVE-2026-6134?
CVE-2026-6134 is a stack-based buffer overflow vulnerability.
How can CVE-2026-6134 impact Tenda F451 devices?
CVE-2026-6134 can allow remote attackers to execute arbitrary code due to a buffer overflow.
What software is affected by CVE-2026-6134?
CVE-2026-6134 affects Tenda F451 with firmware version 1.0.0.7_cn_svn7958.
How do I remediate CVE-2026-6134?
To remediate CVE-2026-6134, it is recommended to update the Tenda F451 firmware to a patched version.