Description
A vulnerability was detected in Tenda F456 1.0.0.5. Affected is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. Performing a manipulation of the argument dips results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Published: 2026-04-27
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via HTTP buffer overflow
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a buffer overflow in the httpd component of the Tenda F456 router, triggered by manipulating the dips argument to the fromGstDhcpSetSer function in /goform/GstDhcpSetSer. The flaw allows an attacker to overwrite memory on remote systems, potentially leading to arbitrary code execution. It is categorized as CWE‑119 and CWE‑120. The CVSS score of 8.7 indicates a high severity impact on confidentiality, integrity, and availability.

Affected Systems

The affected product is the Tenda F456 router running firmware version 1.0.0.5. No other vendor or product versions are listed as impacted in the CVE data.

Risk and Exploitability

The CVSS score of 8.7 denotes a high risk, but the EPSS score of <1% indicates a low probability of widespread exploitation at present. Because the exploit is publicly documented, remote attackers can target the router over the network by sending crafted HTTP requests to the vulnerable endpoint. The vulnerability is not listed in the CISA KEV catalog, however it remains a significant threat if mitigated. The likely attack vector is remote through the router’s web management interface.

Generated by OpenCVE AI on April 28, 2026 at 04:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the latest firmware release from Tenda that contains the fix for this buffer overflow.
  • Restrict remote access to the router’s web interface by allowing only local network traffic; block or filter the /goform/GstDhcpSetSer endpoint from external networks.
  • Monitor network traffic for abnormal requests to the vulnerable endpoint and enforce additional firewall or IDS rules to block suspicious activity.

Generated by OpenCVE AI on April 28, 2026 at 04:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Apr 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda f456 Firmware
CPEs cpe:2.3:h:tenda:f456:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:f456_firmware:1.0.0.5:*:*:*:*:*:*:*
Vendors & Products Tenda f456 Firmware

Mon, 27 Apr 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda f456
Vendors & Products Tenda
Tenda f456

Mon, 27 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Apr 2026 04:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Tenda F456 1.0.0.5. Affected is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. Performing a manipulation of the argument dips results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Title Tenda F456 httpd GstDhcpSetSer fromGstDhcpSetSer buffer overflow
Weaknesses CWE-119
CWE-120
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Tenda F456 F456 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-27T13:21:43.396Z

Reserved: 2026-04-26T08:00:19.267Z

Link: CVE-2026-7081

cve-icon Vulnrichment

Updated: 2026-04-27T13:21:37.414Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-27T04:16:09.263

Modified: 2026-04-30T14:30:56.150

Link: CVE-2026-7081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T05:00:14Z

Weaknesses