Description
A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Problem types
Product status
1.0.0.9
Timeline
| 2026-06-08: | Advisory disclosed |
| 2026-06-08: | VulDB entry created |
| 2026-06-08: | VulDB entry last update |
Credits
hacker128 (VulDB User)
References
vuldb.com/vuln/369166 (VDB-369166 | Tenda F451 Web Management WriteFacMac formWriteFacMac os command injection)
vuldb.com/vuln/369166/cti (VDB-369166 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-11556 (CVE-2026-11556 | CVE Analysis and Report)
vuldb.com/submit/836476 (Submit #836476 | Tenda Tenda F451 Wireless Router V1.0.0.7, V1.0.0.9 OS Command Injection)
github.com/...orts/Tenda/formWriteFacMac2/formWriteFacMac.md
www.tenda.com.cn/