CVE-2026-7101
גבוהה 8.8
תיאור (מקור, אנגלית)
A vulnerability has been found in Tenda F456 1.0.0.5. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. The manipulation leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
7.4 (HIGH)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 1% (אחוזון 000) נכון ל-30/7/2026
- CWE
- CWE-119, CWE-120
מוצרים מושפעים
tenda: f456 firmware; tenda: f456
קישורים
- https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_139/README.md ExploitThird Party Advisory
- https://vuldb.com/submit/798474 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359676 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359676/cti Permissions RequiredVDB Entry
- https://www.tenda.com.cn/ Product