CVE-2026-5989 is a stack-based buffer overflow vulnerability affecting Tenda F451 router firmware version 1.0.0.7. The flaw exists in the fromRouteStatic function of the /goform/RouteStatic endpoint, where improper validation of the page parameter allows remote code execution. This vulnerability carries a CVSS score of 8.8 (HIGH), indicating significant risk. It requires network accessibility and low-privilege user authentication but poses no complexity for exploitation. Successful attacks could result in complete compromise of confidentiality, integrity, and availability on affected systems. Currently, the vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog and shows no indication of active exploitation. However, proof-of-concept exploit code has been publicly disclosed, which increases the risk of opportunistic attacks. The relatively low EPSS score of 0.00048 suggests limited near-term exploitation probability, though the published exploit nature warrants timely patching for organizations using vulnerable Tenda F451 devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.7CPE matchmatch criteria | cpe:2.3:o:tenda:f451_firmware:1.0.0.7:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.