CVE-2026-7097: Tenda F456 httpd webExcptypemanFilter fromwebExcptypemanFilter buffer overflow
A weakness has been identified in Tenda F456 1.0.0.5. This issue affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter of the component httpd. This manipulation of the argument page causes buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7097?
CVE-2026-7097 is identified as a high severity vulnerability due to its buffer overflow impact.
How do I fix CVE-2026-7097?
To fix CVE-2026-7097, users should upgrade the Tenda F456 firmware to the latest version that addresses this vulnerability.
What component is affected by CVE-2026-7097?
CVE-2026-7097 affects the httpd component specifically through the fromwebExcptypemanFilter function.
What is the impact of exploiting CVE-2026-7097?
Exploiting CVE-2026-7097 can lead to arbitrary code execution resulting from the buffer overflow.
Which version of the Tenda F456 is vulnerable to CVE-2026-7097?
Version 1.0.0.5 of the Tenda F456 is the only version known to be vulnerable to CVE-2026-7097.