


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in Tenda F456 1.0.0.5. The impacted element is the function fromNatlimitof of the file /goform/Natlimit of the component httpd. Executing …
Published:
26 April 2026 at 22:00:00
Alert date:
27 April 2026 at 19:18:12
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A critical buffer overflow vulnerability has been discovered in Tenda F456 router firmware version 1.0.0.5. The flaw exists in the fromNatlimitof function within the /goform/Natlimit file of the httpd component. This vulnerability can be exploited remotely through manipulation of the affected function. The security flaw allows attackers to cause buffer overflow conditions, potentially leading to code execution or system compromise. Public exploit code has been released and is available for use, significantly increasing the risk to affected systems.
Technical details
Mitigation steps:
Affected products:
Tenda F456
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7100
https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_138/README.md
https://vuldb.com/submit/798473
https://vuldb.com/vuln/359675
https://vuldb.com/vuln/359675/cti
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
