BRIEFING NOTE: CVE-2026-5992 A stack-based buffer overflow vulnerability has been identified in Tenda F451 firmware version 1.0.0.7, specifically in the fromP2pListFilter function of the /goform/P2pListFilter endpoint. The vulnerability is triggered through manipulation of the page parameter and allows remote attackers to execute arbitrary code. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring only low complexity and low privilege access. The potential impact is severe, affecting confidentiality, integrity, and availability. Notably, successful exploitation requires authenticated access, which somewhat limits opportunistic attacks. Public exploit code has been disclosed for this vulnerability, increasing risk exposure across deployed Tenda F451 devices. The EPSS score of 0.000480 indicates relatively low predicted exploitation probability in the wild. The vulnerability is not currently listed on the CISA KEV catalog, and community attention appears limited, though the moderate FAUCET Risk Score of 51.0 warrants monitoring.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.7CPE matchmatch criteria | cpe:2.3:o:tenda:f451_firmware:1.0.0.7:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.