


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was detected in Tenda F456 1.0.0.5. The affected element is the function formQuickIndex of the file /goform/QuickIndex of the component httpd. P…
Published:
26 april 2026 om 22:00:00
Alert date:
27 april 2026 om 10:01:58
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A buffer overflow vulnerability (CVE-2026-7099) was discovered in Tenda F456 router version 1.0.0.5. The vulnerability affects the formQuickIndex function in the /goform/QuickIndex file of the httpd component. Attackers can exploit this remotely by manipulating the mit_linktype argument to cause a buffer overflow. The exploit is publicly available, making this a high-priority security issue for affected devices.
Technical details
Mitigation steps:
Affected products:
Tenda F456
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7099
https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_137/README.md
https://vuldb.com/submit/798472
https://vuldb.com/vuln/359674
https://vuldb.com/vuln/359674/cti
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
