CVE-2026-7054: Tenda F456 httpd PPTPDClient fromPptpUserAdd buffer overflow
A weakness has been identified in Tenda F456 1.0.0.5. This vulnerability affects the function fromPptpUserAdd of the file /goform/PPTPDClient of the component httpd. Executing a manipulation of the argument opttype/usernamewith can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7054?
CVE-2026-7054 is classified as a critical buffer overflow vulnerability that may allow remote code execution.
How do I fix CVE-2026-7054?
To mitigate CVE-2026-7054, update the Tenda F456 to version 1.0.0.6 or later which addresses the vulnerability.
What are the potential impacts of exploiting CVE-2026-7054?
Exploiting CVE-2026-7054 may lead to unauthorized access, data leakage, or complete control of the affected device.
Which versions of Tenda F456 are affected by CVE-2026-7054?
CVE-2026-7054 affects Tenda F456 version 1.0.0.5.
What component of Tenda F456 is vulnerable in CVE-2026-7054?
The vulnerable component in CVE-2026-7054 is the httpd function fromPptpUserAdd in the PPTPDClient module.