CVE-2026-7098: Tenda F456 httpd DhcpListClient fromDhcpListClient buffer overflow
A security vulnerability has been detected in Tenda F456 1.0.0.5. Impacted is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. Such manipulation of the argument page leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7098?
CVE-2026-7098 is a critical vulnerability due to a buffer overflow in the Tenda F456 firmware.
How do I fix CVE-2026-7098?
To fix CVE-2026-7098, update the Tenda F456 to the latest firmware version provided by the vendor.
What components are affected by CVE-2026-7098?
CVE-2026-7098 affects the httpd component, specifically the fromDhcpListClient function in the /goform/DhcpListClient file.
Can CVE-2026-7098 be exploited remotely?
Yes, CVE-2026-7098 can be exploited remotely, allowing attackers to manipulate the buffer overflow vulnerability.
Which version of Tenda F456 is vulnerable to CVE-2026-7098?
Version 1.0.0.5 of Tenda F456 is the version affected by CVE-2026-7098.