CVE-2026-7078Disclosure(tenda / f456)

LOWCVSS 7.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in Tenda F456 1.0.0.5. The impacted element is the function fromSetIpBind of the file /goform/SetIpBind of the component httpd. The manipulation of the argument page results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f456
  • f456_firmware

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
f456f456_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-27: 3Technical Details · 2026-04-27: 104-27
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7078 A security flaw has been discovered in Tenda F456 1.0.0.5. The impacted element is the function fromSetIpBind of the file /goform/SetIpBind of the component httpd. The … https://www.cve.org/CVERecord?id=CVE-2026-7078

    Post summary

    A new vulnerability, CVE‑2026‑7078, has been identified in Tenda F456 routers affecting the fromSetIpBind function in the httpd component; no PoC, exploit, patch, or active exploitation is reported yet.

    0001098
    57.3K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7078 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7078 #CVE-2026-7078 #CVE #High #CyberSecurity #InfoSec https://t.co/WUaQ2iESlp

    Post summary

    The tweet announces CVE-2026-7078, noting its severity score of 8.8 and high risk level affecting unspecified products, with a link to the NVD entry but no further technical or exploitation details.

    0000044
    141 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-7078 A security flaw has been discovered in Tenda F456 1.0.0.5. The impacted element is the function fromSetIpBind of the fi… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-7078 #Tenda #CyberSecurity #InfoSec

    Post summary

    A high‑severity vulnerability, CVE‑2026‑7078, discovered in Tenda F456’s fromSetIpBind function has been announced with a CVSS score of 8.8, but no exploit, patch, or deep technical details are provided yet.

    0000046
    142 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf456---
OStendaf456_firmware1.0.0.5--

Explore more