CVE-2026-7097
גבוהה 8.8
תיאור (מקור, אנגלית)
A weakness has been identified in Tenda F456 1.0.0.5. This issue affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter of the component httpd. This manipulation of the argument page causes buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
7.4 (HIGH)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-119, CWE-120
מוצרים מושפעים
tenda: f456 firmware; tenda: f456
קישורים
- https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_135/README.md ExploitThird Party Advisory
- https://vuldb.com/submit/798470 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359672 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359672/cti Permissions RequiredVDB Entry
- https://www.tenda.com.cn/ Product