CVE-2026-7099: Tenda F456 httpd QuickIndex formQuickIndex buffer overflow
A vulnerability was detected in Tenda F456 1.0.0.5. The affected element is the function formQuickIndex of the file /goform/QuickIndex of the component httpd. Performing a manipulation of the argument mitlinktype results in buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7099?
CVE-2026-7099 is classified as a critical vulnerability due to the potential for remote code execution through buffer overflow.
How do I fix CVE-2026-7099?
To fix CVE-2026-7099, update your Tenda F456 device to the latest firmware version provided by the vendor.
What systems are affected by CVE-2026-7099?
CVE-2026-7099 affects the Tenda F456 device specifically on version 1.0.0.5.
What type of vulnerability is CVE-2026-7099?
CVE-2026-7099 is a buffer overflow vulnerability found in the QuickIndex function of the Tenda F456’s HTTP daemon.
Can CVE-2026-7099 be exploited remotely?
Yes, CVE-2026-7099 can be exploited remotely by manipulating arguments sent to the vulnerable QuickIndex function.