CVE-2026-6134: Tenda F451 qossetting fromqossetting stack-based overflow

Published Apr 12, 2026
·
Updated

A security flaw has been discovered in Tenda F451 1.0.0.7cnsvn7958. This vulnerability affects the function fromqossetting of the file /goform/qossetting. Performing a manipulation of the argument qos results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

Affected Software

3 affected components
Tenda F451=1.0.0.7_cn_svn7958
All of the following
Tenda F451 Firmware=1.0.0.7
Tenda F451

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Tenda F451 to a version that resolves this vulnerability.

    Fixed in 1.0.0.7_cn_svn7958
  2. Compensating control

    Since the vulnerability is remotely exploitable via /goform/qossetting (function fromqossetting), restrict network access to the router’s web management/API endpoint to only trusted sources (e.g., block at firewall/ACL and allow only required IPs).

  3. Operational

    If this device is exposed and the exploit is publicly available, check for signs of exploitation and reset/reconfigure any impacted settings; monitor logs around requests to /goform/qossetting (fromqossetting) after mitigation.

Event History

Apr 12, 2026
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-6134?

CVE-2026-6134 has a severity rating of high, with a score of 7.4.

2

What type of vulnerability is described in CVE-2026-6134?

CVE-2026-6134 is a stack-based buffer overflow vulnerability.

3

How can CVE-2026-6134 impact Tenda F451 devices?

CVE-2026-6134 can allow remote attackers to execute arbitrary code due to a buffer overflow.

4

What software is affected by CVE-2026-6134?

CVE-2026-6134 affects Tenda F451 with firmware version 1.0.0.7_cn_svn7958.

5

How do I remediate CVE-2026-6134?

To remediate CVE-2026-6134, it is recommended to update the Tenda F451 firmware to a patched version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203