CVE-2026-7101Disclosure(tenda / f456)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in Tenda F456 1.0.0.5. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. The manipulation leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f456
  • f456_firmware

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-04-27); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
f456f456_firmware

2 versions affected across 2 products

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-26: 1Mentions · 2026-04-27: 4Mentions · 2026-05-25: 1Technical Details · 2026-04-27: 4Technical Details · 2026-05-25: 104-2604-2705-25
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-261
Disclosure1
2026-04-274
Disclosure3General1
2026-05-251
Disclosure1
Full discourse6 posts
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Tenda F456 (CVE-2026-7101) https://vuldb.com/vuln/359676

    Post summary

    A new vulnerability (CVE-2026-7101) with elevated criticality affecting the Tenda F456 router has been reported, but no further details are provided in the statement.

    01010112
    2.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-7101 · v1.0.0.5 → 8.8 Tenda F456 router (v1.0.0.5) is vulnerable to unauthenticated remote buffer overflow in the management endpoint /goform/WrlclientSet (CVSS 8.8).

    Post summary

    The post discloses a CVE-2026-7101 vulnerability in the Tenda F456 router (v1.0.0.5), detailing an unauthenticated remote buffer overflow in the /goform/WrlclientSet endpoint with a CVSS score of 8.8.

    1000042
    227 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-7101 A vulnerability has been found in Tenda F456 1.0.0.5. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. The manipulati… https://www.cve.org/CVERecord?id=CVE-2026-7101 ----- Traducción: CVE-2026-7101 Se … http://infoflow.cloud`

    Post summary

    The snippet announces CVE-2026-7101 affecting Tenda F456, detailing the affected component and function, but provides no exploit, patch, or active exploitation information.

    0000031
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7101 A vulnerability has been found in Tenda F456 1.0.0.5. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. The manipulati… https://www.cve.org/CVERecord?id=CVE-2026-7101

    Post summary

    The text announces CVE‑2026‑7101 affecting the Tenda F456 1.0.0.5 router’s httpd component, noting the impacted function and firmware version, but does not include PoC, exploit, patch, or active use details.

    00000117
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7101 Remote Buffer Overflow in Tenda F456 1.0.0.5 httpd Component https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7101

    Post summary

    CVE-2026-7101 describes a remote buffer overflow vulnerability in the Tenda F456 1.0.0.5 httpd component, with no PoC, exploit, active exploitation, or patch information provided.

    0000053
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-7101 A vulnerability has been found in Tenda F456 1.0.0.5. This affects the function fromWrlclientSet of the file /goform/Wr… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-7101 #Tenda #CyberSecurity #InfoSec

    Post summary

    A high‑severity vulnerability (CVE‑2026‑7101) affecting the fromWrlclientSet function of Tenda F456 has been identified, with a CVSS score of 8.8; a full analysis is referenced in the link.

    0000043
    142 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf456---
OStendaf456_firmware1.0.0.5--

Explore more