


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was detected in Tenda F456 1.0.0.5. Impacted is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter of the component httpd. The man…
Published:
25 april 2026 om 22:00:00
Alert date:
26 april 2026 om 23:04:05
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A buffer overflow vulnerability has been identified in Tenda F456 router firmware version 1.0.0.5. The vulnerability affects the fromSafeUrlFilter function in the /goform/SafeUrlFilter file of the httpd component. An attacker can exploit this by manipulating the 'page' argument to trigger a buffer overflow. The vulnerability can be exploited remotely, making it particularly dangerous. Public exploits are now available, increasing the risk of active exploitation. This affects network infrastructure devices commonly used in home and small business environments.
Technical details
Mitigation steps:
Affected products:
Tenda F456
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7056
https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_127/README.md
https://vuldb.com/submit/798458
https://vuldb.com/submit/798462
https://vuldb.com/vuln/359629
https://vuldb.com/vuln/359629/cti
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
