Junglewise Threat Intelligence

CVE-2026-6200: Tenda F456 stack buffer overflow in formwebtypelibrary

CVE-2026-6200 · Severity: high · CVSS 8.8 · Published 2026-04-13

Vendors: Tenda.

Executive brief

A vulnerability exists in the Tenda F456 router, a device used for home and small office networking. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of internet connectivity or the unauthorized interception of network traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda F456 router (version 1.0.0.5) within the 'formwebtypelibrary' function of the '/goform/webtypelibrary' component. The issue stems from the improper use of the 'strcat' function when processing the 'webSiteId' (or 'menufacturer/Go') parameter, which lacks sufficient length validation before being copied into a fixed-size stack buffer. A remote attacker with low privileges can exploit this by sending a crafted POST request to trigger the overflow. Successful exploitation can lead to a denial of service (DoS) or arbitrary remote code execution (RCE). A public exploit (PoC) has been disclosed.

Affected products

  • Tenda F456 1.0.0.5

Timeline

  • 2026-04-13: disclosed: Vulnerability disclosed and CVE assigned.
  • 2026-04-13: advisory

References