Buffer Overflow Flaw in Tenda F456 by Tenda
CVE-2026-7053
Key Information:
Badges
What is CVE-2026-7053?
A critical security flaw exists in the Tenda F456 router, specifically in the function frmL7ProtForm of the httpd component located at /goform/L7Prot. This vulnerability allows remote attackers to exploit a buffer overflow by manipulating the 'page' argument. Such exploitation can lead to unauthorized access and control over affected systems. Publicly released exploits may facilitate these attacks, emphasizing the urgency for users to apply necessary security patches promptly.
Affected Version(s)
F456 1.0.0.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved