A vulnerability was found in Tenda FH451 1.0.0.9. This impacts the function fromSetCfm of the file /goform/setcfm. The manipulation of the argument funcname/funcpara1 results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.
Published: 2026-03-07
CVSS: 9.0
CVSS Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C
Download Exploit for CVE-2026-3677 here:
Use Tor Browser to access .onion site.
https://sonitex.com/exploit-209-cve-2026-26222/
https://sonitex.com/exploit-54-cve-2026-2854/
https://sonitex.com/exploit-206-cve-2026-27587/