


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in Tenda F456 1.0.0.5. This affects the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing…
Published:
25 april 2026 om 22:00:00
Alert date:
26 april 2026 om 23:04:07
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A critical security vulnerability has been identified in Tenda F456 router version 1.0.0.5. The flaw affects the frmL7ProtForm function in the /goform/L7Prot file of the httpd component. Attackers can exploit this vulnerability by manipulating the 'page' argument, which leads to a buffer overflow condition. The vulnerability allows for remote exploitation, making it particularly dangerous. Public exploit code has been released and is available for potential attackers to use. This makes the vulnerability a high-priority security concern requiring immediate attention and patching.
Technical details
Mitigation steps:
Affected products:
Tenda F456
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7053
https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_124/README.md
https://vuldb.com/submit/798455
https://vuldb.com/vuln/359626
https://vuldb.com/vuln/359626/cti
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
