Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2026-6120 โ€” AI Deep Analysis Summary

CVSS 8.8 ยท High

Q1What is this vulnerability? (Essence + Consequences)

- **CVE-2026-6120**: Stack-based overflow in `httpd` of **Tenda F451** ๐Ÿšจ - Happens in `DhcpListClient` โ†’ `fromDhcpListClient` - **Consequence**: Full control risk ๐Ÿ’ฅ - Remote code exec possible - Device comproโ€ฆ

Q2Root Cause? (CWE/Flaw)

- **Root Cause**: Stack-based buffer overflow โš ๏ธ - Likely **CWE-121**: Stack buffer overflow - Triggered by crafted input in DHCP client handling ๐Ÿ”

Q3Who is affected? (Versions/Components)

- **Affected Product**: **Tenda F451** router ๐Ÿ“ถ - Component: `httpd` service - Firmware: `F451_kfw_V1.0.0.7_cn_svn7958 V1.0.0.7` ๐Ÿงฉ - Others unconfirmed โ“

Q4What can hackers do? (Privileges/Data)

- **Hackers can**: - Gain **high impact** ๐Ÿšจ - **Privilege**: Auth user (PR:L) โ†’ full control - Access, modify, delete **data** ๐Ÿ’พ - Execute arbitrary code ๐Ÿ–ฅ๏ธ

Q5Is exploitation threshold high? (Auth/Config)

- **Exploitation threshold**: LOW โœ… - **Attack Vector**: Network (AV:N) - **Attack Complexity**: Low (AC:L) - **Privileges Required**: Low (PR:L) - **No User Interaction** (UI:N) ๐ŸŽฏ

Q6Is there a public Exp? (PoC/Wild Exploitation)

- **Public Exploit**: YES ๐Ÿšจ - Ref: `https://github.com/Jimi-Lab/cve/issues/11` ๐Ÿ”— - Tagged: `exploit`, `issue-tracking` - No PoC listed in `pocs` field but GitHub shows activity ๐Ÿงช

Q7How to self-check? (Features/Scanning)

- **Self-check**: - Check firmware = `V1.0.0.7` ๐Ÿ” - Monitor `httpd` crashes/log anomalies ๐Ÿง  - Scan w/ signature from `VDB-356983/cti` ๐Ÿ›ก๏ธ - Look for DHCP list parsing issues ๐Ÿ“‹

Q8Is it fixed officially? (Patch/Mitigation)

- **Official Fix**: NOT mentioned ๐Ÿšซ - No patch info in refs/tags - Advisory exists, but no fix link ๐Ÿ“ญ - Status: **Unpatched** โŒ

Q9What if no patch? (Workaround)

- **Workaround if no patch**: - Restrict access to `httpd` port ๐Ÿšท - Disable unused DHCP features ๐Ÿ›‘ - Apply firewall rules at network edge ๐Ÿงฑ - Monitor & alert on abnormal DHCP requests ๐Ÿ””

Q10Is it urgent? (Priority Suggestion)

- **Urgency**: HIGH ๐Ÿ”ฅ - CVSS: `9.0` range (H/H/H) ๐Ÿ’ฅ - Public exploit + remote + no patch = ๐Ÿšจ - **Priority**: Patch ASAP or isolate device ๐Ÿ›ก๏ธโฐ