CVE-2026-6137: Tenda F451 AdvSetWan fromAdvSetWan stack-based overflow
Published Apr 12, 2026
·Updated
A vulnerability was detected in Tenda F451 1.0.0.7cnsvn7958. The affected element is the function fromAdvSetWan of the file /goform/AdvSetWan. The manipulation of the argument wanmode/PPPOEPassword results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used.
Affected Software
3 affected components
Tenda Tenda F451=1.0.0.7_cn_svn7958
All of the following
Tenda F451 Firmware=1.0.0.7
Tenda F451
Event History
Apr 12, 2026
CVE Published
via MITRE·11:45 PM
Data Sourced
via MITRE·11:45 PM
DescriptionSeverityWeakness
Apr 13, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeaknessAffected Software
Apr 15, 58301
Event
via FIRST·02:08 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-6137?
The severity of CVE-2026-6137 is rated as high with a score of 7.4.
2
How do I fix CVE-2026-6137?
To fix CVE-2026-6137, you should update the Tenda F451 firmware to the latest version provided by the vendor.
3
What type of vulnerability is CVE-2026-6137?
CVE-2026-6137 is a buffer overflow vulnerability.
4
Can CVE-2026-6137 be exploited remotely?
Yes, CVE-2026-6137 can be exploited remotely.
5
What components of Tenda F451 are affected by CVE-2026-6137?
CVE-2026-6137 affects the function fromAdvSetWan in the file /goform/AdvSetWan.