CVE-2026-6200: Tenda F456 webtypelibrary formwebtypelibrary stack-based overflow
A vulnerability was determined in Tenda F456 1.0.0.5. The affected element is the function formwebtypelibrary of the file /goform/webtypelibrary. This manipulation of the argument menufacturer/Go causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6200?
CVE-2026-6200 is classified as a critical vulnerability due to its potential to allow arbitrary code execution through stack-based buffer overflow.
How does CVE-2026-6200 affect Tenda F456 devices?
CVE-2026-6200 affects Tenda F456 devices running version 1.0.0.5, specifically targeting the formwebtypelibrary function.
How do I fix CVE-2026-6200?
To mitigate CVE-2026-6200, users should update the Tenda F456 firmware to the latest version provided by the vendor.
What is a stack-based buffer overflow in relation to CVE-2026-6200?
In CVE-2026-6200, a stack-based buffer overflow occurs when the function formwebtypelibrary improperly handles input, leading to potential code execution.
Are there any specific mitigations for CVE-2026-6200?
In addition to firmware updates, it is recommended to change default credentials and apply network-layer protections to mitigate CVE-2026-6200.