CVE-2026-7081

· NIST NVD ↗

A vulnerability was detected in Tenda F456 1.0.0.5. Affected is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. Performing a manipulation of the argument dips results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.

HIGH
CVSS severity
8.8
CVSS base score
2026-04-27
Published

CWE codes

CWE-119CWE-120

Affected products

tenda:f456_firmwaretenda:f456

Sources