CVE-2026-6632: Tenda f451

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability was identified in Tenda F451 1.0.0.7_cn_svn7958. The affected element is the function fromSafeClientFilter of the file /goform/SafeClientFilter of the component httpd. The manipulation of the argument menufacturer/Go leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Affected products

  • Tenda f451: version 1.0.0.7_cn_svn7958 only

Published 2026-04-20. Last modified 2026-06-17.