HIGH
Tenda F456 httpd webExcptypemanFilter fromwebExcptypemanFilter buffer overflow
Published Apr 27, 2026
8.7
HIGHCVSS 4.0
EPSS 1.01%
Description
A weakness has been identified in Tenda F456 1.0.0.5. This issue affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter of the component httpd. This manipulation of the argument page causes buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected products
-
- Version 1.0.0.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Tenda | n/a | n/a |
|
AND
- 1.0.0.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25788 Advisory
- https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_135/README.md exploitThird Party Advisory
- https://vuldb.com/submit/798470 third-party-advisoryThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359672 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359672/cti signaturepermissions-requiredPermissions RequiredVDB Entry
- https://www.tenda.com.cn/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25788 | Advisory | |
| https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_135/README.md | exploitThird Party Advisory | |
| https://vuldb.com/submit/798470 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/359672 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/359672/cti | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://www.tenda.com.cn/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Apr 27, 2026
Updated Apr 29, 2026
Reserved Apr 26, 2026
Link CVE-2026-7097
CISA Vulnrichment
Updated Apr 29, 2026
ENISA EUVD
EUVD-2026-25788 Assigner VulDB
Published Apr 27, 2026
Updated Apr 29, 2026
Exploited since n/a
Link EUVD-2026-25788