Junglewise Threat Intelligence

CVE-2026-9389: Tenda F456 buffer overflow in frmL7ImForm

CVE-2026-9389 · Severity: high · CVSS 8.8 · Published 2026-05-24

Vendors: Tenda.

Executive brief

A security vulnerability exists in the Tenda F456 router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to crash the router or potentially take full control of the device. This could lead to a complete loss of internet access or the interception of network traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the 'httpd' service of Tenda F456 firmware version 1.0.0.5. The flaw is located within the 'frmL7ImForm' function in the '/goform/L7Im' component. The vulnerability is caused by the unsafe use of 'sprintf' when processing the 'page' parameter, which lacks proper length validation before being copied into a fixed-size stack buffer. A remote attacker with low privileges can exploit this by sending a specially crafted POST request, potentially leading to remote code execution (RCE) or a denial of service (DoS). Public exploit code (PoC) has been disclosed.

Affected products

  • Tenda F456 1.0.0.5

Timeline

  • 2026-05-24: disclosed: Public disclosure of the vulnerability and PoC.
  • 2026-05-24: advisory

References

Related threats