← Vulnerability feed

Vulnerability record · CVE-2026-5988 · published 9 April 2026

CVE-2026-5988: Tenda f451 firmware memory buffer overflow vulnerability

Tenda · F451 Firmware

A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Performing a manipulation of the argument mit_ssid results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

7.4 CVSS 4.0 High EPSS 0.95% · top 40.4% CWE-119 · Memory buffer overflowCWE-121 · Stack-based buffer overflow
7.4CVSS 4.0 base score, v2 9.0
0.95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Performing a manipulation of the argument mit_ssid results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/Jimi-Lab/cve/issues/4 Broken Link
https://vuldb.com/submit/792857 Third Party AdvisoryVDB Entry
https://vuldb.com/vuln/356542 Third Party AdvisoryVDB Entry
https://vuldb.com/vuln/356542/cti Permissions RequiredVDB Entry
https://www.tenda.com.cn/ Product

Track CVE-2026-5988 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.4CVE-2026-6136Tenda f451 firmware memory buffer overflow vulnerabilityA security vulnerability has been detected in Tenda F451 1.0.0.7_cn_svn7958. Impacted is the function frmL7ImForm of the file /goform/L7Im. The manip…EPSS 0.95%7.4CVE-2026-6137Tenda f451 firmware memory buffer overflow vulnerabilityA vulnerability was detected in Tenda F451 1.0.0.7_cn_svn7958. The affected element is the function fromAdvSetWan of the file /goform/AdvSetWan. The …EPSS 0.95%7.4CVE-2026-6135Tenda f451 firmware memory buffer overflow vulnerabilityA weakness has been identified in Tenda F451 1.0.0.7_cn_svn7958. This issue affects the function fromSetIpBind of the file /goform/SetIpBind. Executi…EPSS 0.95%7.4CVE-2026-6133Tenda f451 firmware memory buffer overflow vulnerabilityA vulnerability was identified in Tenda F451 1.0.0.7_cn_svn7958. This affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Such …EPSS 0.95%7.4CVE-2026-6134Tenda f451 firmware memory buffer overflow vulnerabilityA security flaw has been discovered in Tenda F451 1.0.0.7_cn_svn7958. This vulnerability affects the function fromqossetting of the file /goform/qoss…EPSS 0.95%7.4CVE-2026-6124Tenda f451 firmware memory buffer overflow vulnerabilityA vulnerability was determined in Tenda F451 1.0.0.7. This vulnerability affects the function fromSafeMacFilter of the file /goform/SafeMacFilter of …EPSS 0.95%7.4CVE-2026-6123Tenda f451 firmware memory buffer overflow vulnerabilityA vulnerability was found in Tenda F451 1.0.0.7. This affects the function fromAddressNat of the file /goform/addressNat of the component httpd. Perf…EPSS 0.96%7.4CVE-2026-6122Tenda f451 firmware memory buffer overflow vulnerabilityA vulnerability has been found in Tenda F451 1.0.0.7. Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the componen…EPSS 0.95%

Source: NIST National Vulnerability Database (record CVE-2026-5988), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.