A vulnerability has been found in Tenda F456 1.0.0.5. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. The manipulation leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_139/README.md | Exploit Vendor Advisory |
| https://vuldb.com/submit/798474 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/359676 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/359676/cti | Permissions Required VDB Entry |
| https://www.tenda.com.cn/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
29 Apr 2026, 17:42
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:tenda:f456_firmware:1.0.0.5:*:*:*:*:*:*:* cpe:2.3:h:tenda:f456:-:*:*:*:*:*:*:* |
|
| First Time |
Tenda
Tenda f456 Tenda f456 Firmware |
|
| References | () https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_139/README.md - Exploit, Vendor Advisory | |
| References | () https://vuldb.com/submit/798474 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/359676 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/359676/cti - Permissions Required, VDB Entry | |
| References | () https://www.tenda.com.cn/ - Product |
27 Apr 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-27 09:16
Updated : 2026-04-29 17:42
NVD link : CVE-2026-7101
Mitre link : CVE-2026-7101
CVE.ORG link : CVE-2026-7101
JSON object : View
Products Affected
tenda
- f456_firmware
- f456
