CVE-2026-7099
A vulnerability was detected in Tenda F456 1.0.0.5. The affected element is the function formQuickIndex of the file /goform/QuickIndex of the component httpd. Performing a manipulation of the argument mit_linktype results in buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
View on NVDAnalysis
This vulnerability affects specific Tenda router firmware and is not related to the software development or server infrastructure stack used by the community. While it is a high-severity remote buffer overflow with a public exploit, the impact is limited to users of this specific consumer hardware.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCWE-119CWE-120EPSS
Affects
tenda:f456_firmwaretenda:f456Technical description
A vulnerability was detected in Tenda F456 1.0.0.5. The affected element is the function formQuickIndex of the file /goform/QuickIndex of the component httpd. Performing a manipulation of the argument mit_linktype results in buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.