CVE-2026-6197: Tenda F456 AdvSetWrlsafeset formWrlsafeset stack-based overflow
A flaw has been found in Tenda F456 1.0.0.5. This vulnerability affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Executing a manipulation of the argument mitssid can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6197?
CVE-2026-6197 is classified as a high severity vulnerability due to the potential for stack-based buffer overflow.
How does CVE-2026-6197 affect Tenda F456?
CVE-2026-6197 affects the Tenda F456 by allowing an attacker to exploit the formWrlsafeset function to cause a stack-based buffer overflow.
How do I fix CVE-2026-6197?
To fix CVE-2026-6197, update the Tenda F456 firmware to the latest version provided by Tenda.
What type of attack is possible with CVE-2026-6197?
CVE-2026-6197 allows for a remote code execution attack due to the stack-based buffer overflow vulnerability.
Is there a workaround for CVE-2026-6197?
Currently, there is no recommended workaround for CVE-2026-6197 aside from updating the firmware.