CVE-2026-11557: fallo de gravedad alta en Tenda F451
Tenda F451 Web Management Natlimit fromNatlimit stack-based overflow
Publicada el
41Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 8.7epss 0.5%
probabilidad de explotación
0.5%top 61% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the file /goform/Natlimit of the component Web Management Interface. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Productos afectados
Tenda · F451PoCs públicas encontradas — 1
cve_referencegithub.com/Robots10/IoT_vlu/blob/main/reports/Tenda/fromNatlimit/fromNatlimit.mdno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — Tenda F451
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-11556HIGHTenda F451 Web Management WriteFacMac formWriteFacMac os command injectionEPSS 1.6%CVE-2026-6123HIGHTenda F451 httpd addressNat fromAddressNat stack-based overflowEPSS 1.0%CVE-2026-6137HIGHTenda F451 AdvSetWan fromAdvSetWan stack-based overflowEPSS 0.9%CVE-2026-6136HIGHTenda F451 L7Im frmL7ImForm stack-based overflowEPSS 0.9%CVE-2026-6135HIGHTenda F451 SetIpBind fromSetIpBind stack-based overflowEPSS 0.9%CVE-2026-6134HIGHTenda F451 qossetting fromqossetting stack-based overflowEPSS 0.9%