


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in Tenda FH451 1.0.0.9. This impacts the function fromSetCfm of the file /goform/setcfm. The manipulation of the argument funcname/fun…
Published:
6 maart 2026 om 23:00:00
Alert date:
7 maart 2026 om 23:01:03
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A stack-based buffer overflow vulnerability was discovered in Tenda FH451 router version 1.0.0.9. The vulnerability affects the fromSetCfm function in the /goform/setcfm file, where manipulation of the funcname/funcpara1 arguments leads to buffer overflow. The vulnerability can be exploited remotely and public exploits are available. This poses a high security risk as attackers can potentially execute arbitrary code or cause denial of service on affected devices. The vulnerability has been assigned CVE-2026-3677 and affects network infrastructure equipment widely used in home and small office environments.
Technical details
Mitigation steps:
Affected products:
Tenda FH451
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-3677
https://github.com/Litengzheng/vul_db/blob/main/FH451/vul_61/README.md
https://vuldb.com/?ctiid.349579
https://vuldb.com/?id.349579
https://vuldb.com/?submit.765329
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
