{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-11556","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-06-08T05:55:33.297Z","datePublished":"2026-06-08T18:00:15.317Z","dateUpdated":"2026-06-09T14:35:15.927Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-06-08T18:00:15.317Z"},"title":"Tenda F451 Web Management WriteFacMac formWriteFacMac os command injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-78","lang":"en","description":"OS Command Injection"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-77","lang":"en","description":"Command Injection"}]}],"affected":[{"vendor":"Tenda","product":"F451","versions":[{"version":"1.0.0.7","status":"affected"},{"version":"1.0.0.9","status":"affected"}],"cpes":["cpe:2.3:o:tenda:f451_firmware:*:*:*:*:*:*:*:*"],"modules":["Web Management Interface"]}],"descriptions":[{"lang":"en","value":"A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":8.7,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P","baseSeverity":"HIGH"}},{"cvssV3_1":{"version":"3.1","baseScore":8.8,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R","baseSeverity":"HIGH"}},{"cvssV3_0":{"version":"3.0","baseScore":8.8,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R","baseSeverity":"HIGH"}},{"cvssV2_0":{"version":"2.0","baseScore":9,"vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-06-08T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-06-08T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-06-08T08:00:44.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"hacker128 (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/vuln/369166","name":"VDB-369166 | Tenda F451 Web Management WriteFacMac formWriteFacMac os command injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/369166/cti","name":"VDB-369166 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-11556","name":"CVE-2026-11556 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/836476","name":"Submit #836476 | Tenda Tenda F451 Wireless Router V1.0.0.7, V1.0.0.9 OS Command Injection","tags":["third-party-advisory"]},{"url":"https://github.com/Robots10/IoT_vlu/blob/main/reports/Tenda/formWriteFacMac2/formWriteFacMac.md","tags":["exploit"]},{"url":"https://www.tenda.com.cn/","tags":["product"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-06-09T14:33:10.240378Z","id":"CVE-2026-11556","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-06-09T14:35:15.927Z"}}]}}