Junglewise Threat Intelligence

CVE-2026-6199: Tenda F456 stack overflow in fromqossetting

CVE-2026-6199 · Severity: high · CVSS 8.8 · Published 2026-04-13

Vendors: Tenda.

Executive brief

A vulnerability exists in the Tenda F456 router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to crash the router or potentially take full control of the device. This could lead to a complete loss of internet access for the network or allow an attacker to intercept network traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda F456 router firmware version 1.0.0.5. The flaw is located within the 'fromqossetting' function in the '/goform/qossetting' component. The root cause is the unsafe use of the 'sprintf' function when processing the user-provided 'page' parameter, which lacks proper length validation before being copied into a stack buffer. A remote attacker with low privileges can exploit this by sending a specially crafted POST request to the affected endpoint. Successful exploitation can lead to a denial of service (DoS) or remote code execution (RCE). A public exploit (PoC) is available.

Affected products

  • Tenda F456 1.0.0.5

Timeline

  • 2026-04-13: disclosed: Vulnerability reported via VulDB and NVD

References