Junglewise Threat Intelligence

CVE-2026-6196: Tenda F456 stack-based buffer overflow in fromexeCommand

CVE-2026-6196 · Severity: high · CVSS 8.8 · Published 2026-04-13

Vendors: Tenda.

Executive brief

A vulnerability exists in the Tenda F456 router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to crash the device or potentially take full control of it remotely. This could lead to a complete loss of internet service or unauthorized access to the network traffic passing through the router.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda F456 router (firmware version 1.0.0.5) within the 'fromexeCommand' function of the '/goform/exeCommand' file. The vulnerability is caused by the improper use of the 'strcpy' function, which copies the user-provided 'cmdinput' parameter into a fixed-size stack buffer without performing length validation. A remote attacker with low privileges can exploit this by sending a specially crafted POST request to the affected endpoint. Successful exploitation can lead to a denial of service (DoS) or arbitrary remote code execution (RCE). A public exploit (PoC) is currently available.

Affected products

  • Tenda F456 1.0.0.5

Timeline

  • 2026-04-13: disclosed: Vulnerability published via VulDB and NVD.
  • 2026-04-13: other: Public exploit/PoC released on GitHub.

References