CVE-2026-7101

· NIST NVD ↗

A vulnerability has been found in Tenda F456 1.0.0.5. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. The manipulation leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

HIGH
CVSS severity
8.8
CVSS base score
2026-04-27
Published

CWE codes

CWE-119CWE-120

Affected products

tenda:f456_firmwaretenda:f456

Sources