CVE-2026-6196: Tenda F456 exeCommand fromexeCommand stack-based overflow
A vulnerability was detected in Tenda F456 1.0.0.5. This affects the function fromexeCommand of the file /goform/exeCommand. Performing a manipulation of the argument cmdinput results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6196?
CVE-2026-6196 is classified as a high severity vulnerability due to the potential for a stack-based buffer overflow that could allow remote code execution.
How do I fix CVE-2026-6196?
To mitigate CVE-2026-6196, you should update the Tenda F456 firmware to the latest version available that addresses this vulnerability.
What software versions are affected by CVE-2026-6196?
CVE-2026-6196 specifically affects Tenda F456 version 1.0.0.5.
Can CVE-2026-6196 be exploited remotely?
Yes, CVE-2026-6196 can be exploited remotely by manipulating the cmdinput argument in the exeCommand function.
What are the potential consequences of exploiting CVE-2026-6196?
Exploitation of CVE-2026-6196 could lead to arbitrary code execution on the affected Tenda F456 device.