Tenda FH451 Buffer Overflow Vulnerability in DHCP Server Processing

Vulnerability

A buffer overflow vulnerability has been identified in the Tenda FH451 router, affecting versions through 1.0.0.9. The issue arises in the file '/goform/GstDhcpSetSer', where an unknown input manipulation leads to the overflow. This vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability causes a stack overflow, crashing the router and making it inaccessible. This disruption can be confirmed with Burp Suite, which shows the service is no longer reachable.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/goform/GstDhcpSetSer' endpoint with a crafted 'dips' parameter that exceeds 32 bytes. This can be done using a proof-of-concept script that automates the request.

Added: Feb 22, 2026, 4:20 AM
Updated: Feb 22, 2026, 4:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
9.1
remediation
0.0
relevance
3.1
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.