CVE-2026-7019
8.8Tenda · F456
A buffer overflow vulnerability in the Tenda F456 router allows authenticated attackers to potentially execute arbitrary code or cause a denial of service via the P2pListFilter function.
Executive summary
A critical stack-based buffer overflow in the Tenda F456 router, version 1.0.0.5, poses a significant risk of remote code execution for authenticated users.
Vulnerability
The vulnerability exists within the fromP2pListFilter function of the /goform/P2pListFilter endpoint. An authenticated attacker can trigger a stack-based buffer overflow by providing an excessively long string to the page parameter, as the application fails to perform adequate length validation before passing the input to the sprintf function.
Business impact
Successful exploitation of this flaw allows an attacker to achieve remote code execution on the affected device, potentially leading to a full compromise of the router. Given the CVSS score of 8.8, this vulnerability is classified as High, indicating a severe risk to network integrity. Compromise of network infrastructure can facilitate lateral movement within the environment, data interception, and total loss of device control.
Remediation
Immediate Action: Since a vendor-provided patch is currently unknown, administrators should restrict access to the web management interface and ensure that only trusted users have authenticated access to the device.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/P2pListFilter endpoint and review system logs for signs of service crashes or unauthorized configuration changes.
Compensating Controls: Implement a Web Application Firewall or network-level access control lists to prevent unauthorized or suspicious traffic from reaching the device management interface.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the technical write-up provided in the vulnerability references.
Analyst recommendation
Given the availability of a public proof-of-concept and the high CVSS severity, this vulnerability presents a credible threat to the Tenda F456 router. Organizations should prioritize restricting administrative access to the device and monitor for any vendor announcements regarding a firmware update. Until a formal patch is released, the device should be considered at risk of compromise if exposed to untrusted network segments.
More Tenda CVEs
Sources
Originally found and disclosed by LtzHuster (VulDB User), per the CVE Program record.
- VDB-359598 | Tenda F456 P2pListFilter fromP2pListFilter buffer overflow Vulnerability database entry
- VDB-359598 | CTI Indicators (IOB, IOC, IOA)
- Submit #797473 | Tenda F456 v1.0.0.5 Stack-based Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn