


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in Tenda F456 1.0.0.5. Impacted is the function fromDhcpListClient of the file /goform/DhcpListClient of the componen…
Published:
26 april 2026 om 22:00:00
Alert date:
27 april 2026 om 19:18:12
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A buffer overflow vulnerability has been identified in Tenda F456 router firmware version 1.0.0.5. The vulnerability affects the fromDhcpListClient function in the /goform/DhcpListClient file of the httpd component. Attackers can exploit this flaw by manipulating the 'page' argument, causing a buffer overflow condition. The vulnerability can be exploited remotely, making it particularly dangerous. Public exploits have been disclosed and are available for use, increasing the risk of active exploitation. This affects network infrastructure devices that are commonly deployed in home and small business environments.
Technical details
Mitigation steps:
Affected products:
Tenda F456
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7098
https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_136/README.md
https://vuldb.com/submit/798471
https://vuldb.com/vuln/359673
https://vuldb.com/vuln/359673/cti
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
