CVE-2026-7034: Tenda FH1202 httpd WrlExtraSet stack-based overflow
A vulnerability was found in Tenda FH1202 1.2.0.14(408). Affected by this issue is the function WrlExtraSet of the file /goform/WrlExtraSet of the component httpd. Performing a manipulation of the argument Go results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7034?
CVE-2026-7034 is identified as a critical vulnerability due to its potential for causing stack-based buffer overflow.
How do I fix CVE-2026-7034?
To remediate CVE-2026-7034, update the Tenda FH1202 firmware to the latest version provided by Tenda.
Which devices are affected by CVE-2026-7034?
CVE-2026-7034 affects the Tenda FH1202 running version 1.2.0.14(408).
What are the risks associated with CVE-2026-7034?
Exploitation of CVE-2026-7034 can lead to unauthorized access and execution of arbitrary code on the affected device.
When was CVE-2026-7034 discovered?
CVE-2026-7034 was identified as a vulnerability in the Tenda FH1202 firmware version 1.2.0.14(408) affecting the httpd component.