


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in Tenda F456 1.0.0.5. The affected element is an unknown function of the file /goform/setcfm of the component httpd. This manipulation of…
Published:
25 april 2026 om 22:00:00
Alert date:
26 april 2026 om 23:04:07
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A buffer overflow vulnerability has been discovered in Tenda F456 router version 1.0.0.5. The flaw exists in an unknown function within the /goform/setcfm file of the httpd component. Attackers can exploit this vulnerability by manipulating the funcname/funcpara1 arguments to cause a buffer overflow. The vulnerability can be exploited remotely, and exploit code has already been published and made available to attackers. This poses a significant security risk to affected Tenda F456 devices as remote attackers can potentially compromise the devices without authentication.
Technical details
Mitigation steps:
Affected products:
Tenda F456
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7057
https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_128/README.md
https://vuldb.com/submit/798459
https://vuldb.com/vuln/359630
https://vuldb.com/vuln/359630/cti
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
/goform/setcfm
This article was created with the assistance of AI technology by Perceptive.
