Executive brief
A vulnerability exists in the Tenda F456 router, a device used for home and small office networking. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of internet connectivity or the unauthorized interception of network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda F456 router (version 1.0.0.5) within the 'formwebtypelibrary' function of the '/goform/webtypelibrary' component. The issue stems from the improper use of the 'strcat' function when processing the 'webSiteId' (or 'menufacturer/Go') parameter, which lacks sufficient length validation before being copied into a fixed-size stack buffer. A remote attacker with low privileges can exploit this by sending a crafted POST request to trigger the overflow. Successful exploitation can lead to a denial of service (DoS) or arbitrary remote code execution (RCE). A public exploit (PoC) has been disclosed.
Affected products
- Tenda F456 1.0.0.5
Timeline
- 2026-04-13: disclosed: Vulnerability disclosed and CVE assigned.
- 2026-04-13: advisory