CVE-2026-7056: Tenda F456 httpd SafeUrlFilter fromSafeUrlFilter buffer overflow
A vulnerability was detected in Tenda F456 1.0.0.5. Impacted is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter of the component httpd. The manipulation of the argument page results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7056?
CVE-2026-7056 is classified as a high severity vulnerability due to its potential for causing a buffer overflow.
How do I fix CVE-2026-7056?
To fix CVE-2026-7056, it is recommended to update the Tenda F456 firmware to a version that addresses this vulnerability.
What component is vulnerable in CVE-2026-7056?
The vulnerable component in CVE-2026-7056 is the httpd function fromSafeUrlFilter in the Tenda F456 router.
Can CVE-2026-7056 be exploited remotely?
Yes, CVE-2026-7056 can potentially be exploited remotely due to the nature of the buffer overflow vulnerability.
Which version of Tenda F456 is affected by CVE-2026-7056?
The version affected by CVE-2026-7056 is Tenda F456 version 1.0.0.5.