CVE-2026-7101
high
CVSS v3
8.8
CVSS v2
9.0
VIR risk
8.8
Description
A vulnerability has been found in Tenda F456 1.0.0.5. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. The manipulation leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cna@vuldb.com — https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_139/README.md
References
CWEs
CWE-119 CWE-120
Verify integrity in audit chain (admin only). AS-IS.