CVE-2026-7100Disclosure(tenda / f456)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in Tenda F456 1.0.0.5. The impacted element is the function fromNatlimitof of the file /goform/Natlimit of the component httpd. Executing a manipulation can lead to buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f456
  • f456_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Exploit: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
f456f456_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-27: 4PoC Mentioned / Linked · 2026-04-27: 1Technical Details · 2026-04-27: 404-27
Signal classification2 categories
Disclosure
375.0%
Exploit
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7100 A flaw has been found in Tenda F456 1.0.0.5. The impacted element is the function fromNatlimitof of the file /goform/Natlimit of the component httpd. Executing a manipu… https://www.cve.org/CVERecord?id=CVE-2026-7100 ----- Traducción: CVE-2026-7100 Se … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑7100 affecting Tenda F456’s Natlimit component, giving technical details but no exploit, patch, or PoC information.

    0000032
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7100 A flaw has been found in Tenda F456 1.0.0.5. The impacted element is the function fromNatlimitof of the file /goform/Natlimit of the component httpd. Executing a manipu… https://www.cve.org/CVERecord?id=CVE-2026-7100

    Post summary

    A vulnerability was disclosed in Tenda F456 firmware, detailing the affected function and file but providing no exploit, patch, or proof‑of‑concept information.

    00000103
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Exploit

    CVE-2026-7100 Buffer Overflow in Tenda F456 1.0.0.5 Natlimit Function (Exploitation Published) https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7100

    Post summary

    CVE-2026-7100 is a buffer overflow in the Tenda F456 Natlimit function, with exploitation apparently published, but the text lacks details on active attacks, patches, or a specific exploit tool.

    0000047
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-7100 A flaw has been found in Tenda F456 1.0.0.5. The impacted element is the function fromNatlimitof of the file /goform/Na… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-7100 #Tenda #CyberSecurity #InfoSec

    Post summary

    A new high‑severity vulnerability (CVE‑2026‑7100) was identified in Tenda F456 firmware, with details about the affected function and CVSS score provided; no exploitation or patch information is disclosed.

    0000037
    142 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf456---
OStendaf456_firmware1.0.0.5--

Explore more