Description
A vulnerability was detected in Tenda F456 1.0.0.5. Impacted is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter of the component httpd. The manipulation of the argument page results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2026-04-26: | Advisory disclosed |
| 2026-04-26: | VulDB entry created |
| 2026-04-26: | VulDB entry last update |
Credits
LtzHust (VulDB User)
References
vuldb.com/vuln/359629 (VDB-359629 | Tenda F456 httpd SafeUrlFilter fromSafeUrlFilter buffer overflow)
vuldb.com/vuln/359629/cti (VDB-359629 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/798458 (Submit #798458 | Tenda F456 v1.0.0.5 Stack-based Buffer Overflow)
vuldb.com/submit/798462 (Submit #798462 | Tenda F456 v1.0.0.5 Stack-based Buffer Overflow (Duplicate))
github.com/...eng/vuldb_new/blob/main/F456/vul_127/README.md
www.tenda.com.cn/