CVE-2026-7102: Tenda F456 httpd WriteFacMac FromWriteFacMac command injection
A vulnerability was found in Tenda F456 1.0.0.5. This impacts the function FromWriteFacMac of the file /goform/WriteFacMac of the component httpd. The manipulation of the argument mac results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7102?
CVE-2026-7102 is classified as a high-severity vulnerability due to its potential for command injection.
How do I fix CVE-2026-7102?
To fix CVE-2026-7102, update the Tenda F456 firmware to a version that addresses the vulnerability.
What types of attacks can CVE-2026-7102 be exploited for?
CVE-2026-7102 can be exploited for remote command execution through command injection.
What devices are affected by CVE-2026-7102?
CVE-2026-7102 affects the Tenda F456 router running firmware version 1.0.0.5.
Can CVE-2026-7102 be exploited remotely?
Yes, CVE-2026-7102 can be exploited remotely by an attacker with access to the network.