CVE-2026-7055
high
CVSS v3
8.8
CVSS v2
9.0
VIR risk
8.8
Description
A security vulnerability has been detected in Tenda F456 1.0.0.5. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component httpd. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cna@vuldb.com — https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_126/README.md
References
CWEs
CWE-119 CWE-120
Verify integrity in audit chain (admin only). AS-IS.