Skip to content
CVSS 8.8 · HIGH

CVE-2026-7053

A security flaw has been discovered in Tenda F456 1.0.0.5. This affects the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

View on NVD

Analysis

This is a vulnerability specific to the Tenda F456 consumer router firmware. Per the editorial guidelines, vendor-specific firmware for obscure IoT or home routers is generally not relevant to the professional developer ecosystem unless it indicates a systemic risk.

Severity

Score: 8.8(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-119CWE-120

EPSS

Probability of exploitation (next 30 days): 0.0008 (0.1%)
Percentile: 23.2%
EPSS: 2026-05-06

Affects

tenda:f456_firmwaretenda:f456

Technical description

A security flaw has been discovered in Tenda F456 1.0.0.5. This affects the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

Published: 4/26/2026, 10:17:32 PM
Last modified: 4/29/2026, 10:29:32 PM

References

HomeEventsBlogResourcesTeam