CVE-2026-5990 is a stack-based buffer overflow vulnerability in Tenda F451 router version 1.0.0.7, specifically in the SafeEmailFilter function of the /goform/SafeEmailFilter endpoint. The flaw is triggered through manipulation of the page parameter and allows remote exploitation without requiring special privileges or user interaction. This vulnerability affects a widely-deployed consumer networking device with potential for significant unauthorized system compromise. The vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 8.8, reflecting the network-accessible attack vector, low attack complexity, and ability to achieve confidentiality, integrity, and availability impacts on affected systems. An authenticated user can remotely exploit this flaw to execute arbitrary code or crash the router, potentially leading to complete device compromise or denial of service. Exploitation remains limited in active deployment, as indicated by the low EPSS score and absence from the Known Exploited Vulnerabilities catalog. However, public disclosure of the vulnerability details has occurred, creating a window of risk for coordinated exploitation campaigns. Organizations operating Tenda F451 devices should prioritize firmware updates and network segmentation to mitigate exposure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.7CPE matchmatch criteria | cpe:2.3:o:tenda:f451_firmware:1.0.0.7:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.