CVE-2026-6199: Tenda F456 qossetting fromqossetting stack-based overflow
A vulnerability was found in Tenda F456 1.0.0.5. Impacted is the function fromqossetting of the file /goform/qossetting. The manipulation of the argument page results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6199?
CVE-2026-6199 has a critical severity level due to its potential for remote exploitation through stack-based buffer overflow.
How do I fix CVE-2026-6199?
To fix CVE-2026-6199, update your Tenda F456 firmware to the latest version that addresses this vulnerability.
What systems are affected by CVE-2026-6199?
The only affected system is Tenda F456 running version 1.0.0.5.
What type of vulnerability is CVE-2026-6199?
CVE-2026-6199 is classified as a stack-based buffer overflow vulnerability.
Can CVE-2026-6199 be exploited remotely?
Yes, CVE-2026-6199 can be exploited remotely due to improper handling of the page argument in the fromqossetting function.