CVE-2026-7055: Tenda F456 httpd VirtualSer fromVirtualSer buffer overflow
A security vulnerability has been detected in Tenda F456 1.0.0.5. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component httpd. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7055?
CVE-2026-7055 is classified as a high severity vulnerability due to the potential for remote code execution through a buffer overflow.
How do I fix CVE-2026-7055?
To mitigate CVE-2026-7055, upgrade the Tenda F456 firmware to the latest version provided by Tenda.
Who is affected by CVE-2026-7055?
CVE-2026-7055 affects users of the Tenda F456 router running firmware version 1.0.0.5.
What type of vulnerability is CVE-2026-7055?
CVE-2026-7055 is a buffer overflow vulnerability that can be exploited through manipulation of specific HTTP request parameters.
Can CVE-2026-7055 lead to remote attacks?
Yes, CVE-2026-7055 can potentially enable attackers to execute arbitrary code remotely on the affected device.