Description
A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the file /goform/Natlimit of the component Web Management Interface. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-06-08
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow exists in the fromNatlimit function within the Web Management Interface of Tenda F451 routers. By manipulating the page argument sent to /goform/Natlimit, an attacker can overflow the stack and potentially execute arbitrary code. The vulnerability can be triggered remotely, and exploit code has already been made publicly available, which means a compromised router could become a foothold for further attacks.

Affected Systems

The flaw affects Tenda F451 routers running firmware 1.0.0.7 or 1.0.0.9. These versions are found in the router’s Web Management Interface component. No other firmware versions are reported to be impacted according to the current CNA data.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability. EPSS is not available, but the public availability of exploit code raises the exploitation likelihood. The attack vector is remote via the web interface, and the vulnerability is listed in KEV as not present, reflecting no known mass exploitation yet. Nonetheless, the potential for remote code execution warrants prompt attention.

Generated by OpenCVE AI on June 8, 2026 at 20:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to the latest version that fixes the Natlimit overflow or apply the vendor‑issued patch if available.
  • If a firmware update is not yet available, block or restrict external access to the Web Management Interface, especially the /goform/Natlimit endpoint, using the router’s firewall or access control settings.
  • If possible, disable the Natlimit feature or modify the router configuration to prevent the vulnerable function from being called; alternatively, limit management access to the local network only.
  • Monitor logs for abnormal or unexpected requests to /goform/Natlimit and investigate any suspicious activity.

Generated by OpenCVE AI on June 8, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 08 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda f451
Vendors & Products Tenda f451

Mon, 08 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 08 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the file /goform/Natlimit of the component Web Management Interface. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Title Tenda F451 Web Management Natlimit fromNatlimit stack-based overflow
First Time appeared Tenda
Tenda f451 Firmware
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:o:tenda:f451_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda f451 Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Tenda F451 F451 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-08T19:52:29.251Z

Reserved: 2026-06-08T05:55:39.465Z

Link: CVE-2026-11557

cve-icon Vulnrichment

Updated: 2026-06-08T19:52:22.323Z

cve-icon NVD

Status : Received

Published: 2026-06-08T19:16:41.653

Modified: 2026-06-08T19:16:41.653

Link: CVE-2026-11557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-08T20:30:06Z

Weaknesses