CVE-2026-7057: Tenda F456 httpd setcfm buffer overflow
A flaw has been found in Tenda F456 1.0.0.5. The affected element is an unknown function of the file /goform/setcfm of the component httpd. This manipulation of the argument funcname/funcpara1 causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7057?
CVE-2026-7057 is classified as a high-severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2026-7057?
To fix CVE-2026-7057, update the Tenda F456 to a patched version that addresses the buffer overflow vulnerability.
What is the impact of CVE-2026-7057?
CVE-2026-7057 can lead to remote code execution, allowing attackers to take control of the affected device.
Which devices are affected by CVE-2026-7057?
CVE-2026-7057 affects Tenda F456 devices running version 1.0.0.5.
Is there a workaround for CVE-2026-7057?
Currently, no known workarounds exist for CVE-2026-7057, and the recommended action is to apply the firmware update immediately.