Several high-severity vulnerabilities have been disclosed in the Tenda F456 router running firmware 1.0.0.5, affecting the device’s httpd component across multiple /goform/ endpoints. The flaws include CVE-2026-7053 in frmL7ProtForm via /goform/L7Prot, CVE-2026-7055 in fromVirtualSer via /goform/VirtualSer, CVE-2026-7056 in fromSafeUrlFilter via /goform/SafeUrlFilter, and CVE-2026-7057 in /goform/setcfm. In each case, crafted input to parameters such as page, menufacturer, Go, funcname, or funcpara1 can trigger a buffer overflow.
The vulnerabilities are described as remotely exploitable and have been mapped to CWE-119 and CWE-120, with CVSS scoring indicating high impact to confidentiality, integrity, and availability. Public exploit code has also been reported for all four issues, including references to VulDB and GitHub proof-of-concept material, raising the risk of active attacks against exposed devices. Organizations using affected Tenda F456 routers should treat the flaws as urgent exposure in internet-facing network infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-27, VulDB received CVE-2026-7101 for a remotely exploitable buffer overflow in Tenda F456 firmware 1.0.0.5. The flaw affects the httpd component's fromWrlclientSet function at /goform/WrlclientSet, and the disclosure states that a public exploit exists.
On 2026-04-27, a new CVE entry was recorded for a remotely exploitable buffer overflow in Tenda F456 firmware 1.0.0.5. The flaw affects the httpd component's fromNatlimitof function at /goform/Natlimit, and the disclosure states that a public exploit is already available.
On 2026-04-27, a new CVE entry was recorded for a remotely exploitable buffer overflow in Tenda F456 firmware 1.0.0.5. The flaw affects the httpd component's formQuickIndex function at /goform/QuickIndex via the mit_linktype argument, and the disclosure states that a public exploit is available.
On 2026-04-27, VulDB received CVE-2026-7097 for a remotely exploitable buffer overflow in Tenda F456 firmware 1.0.0.5. The flaw affects the httpd component's fromwebExcptypemanFilter function at /goform/webExcptypemanFilter via the page argument, and the disclosure states that public exploit code is available.
On 2026-04-27, VulDB received CVE-2026-7082 for a remotely exploitable buffer overflow in Tenda F456 firmware 1.0.0.5. The flaw affects the httpd component's formWrlExtraSet function at /goform/WrlExtraSet via the Go argument, and the disclosure states that an exploit is publicly available.
On 2026-04-27, VulDB received CVE-2026-7081 for a remotely exploitable buffer overflow in Tenda F456 firmware 1.0.0.5. The flaw affects the httpd component's fromGstDhcpSetSer function at /goform/GstDhcpSetSer via the dips argument, and the disclosure states that a public exploit exists.
On 2026-04-27, a new CVE entry was recorded for a remotely exploitable buffer overflow in Tenda F456 firmware 1.0.0.5. The flaw affects the httpd component's fromPPTPUserSetting function at /goform/PPTPUserSetting via the delno argument, and public exploit availability was disclosed.
On 2026-04-27, VulDB received CVE-2026-7079 for a remotely exploitable buffer overflow in Tenda F456 firmware 1.0.0.5. The flaw affects the httpd component's fromAdvSetWan function at /goform/AdvSetWan via the wanmode argument, and the disclosure states that a public exploit is available.
On 2026-04-27, VulDB received CVE-2026-7078 for a remotely exploitable buffer overflow in the Tenda F456 httpd component affecting firmware 1.0.0.5. The flaw is in the fromSetIpBind function of /goform/SetIpBind via the page argument, and the disclosure notes public exploit information is available.
The published CVE records state that exploits for the four Tenda F456 vulnerabilities were already publicly available at disclosure time, including references to GitHub proof-of-concept material for some entries. This increased the likelihood of real-world exploitation of the affected router firmware.
On April 26, 2026, vulnerability records were received for four distinct remotely exploitable buffer overflow flaws affecting Tenda F456 firmware 1.0.0.5 in the httpd component: CVE-2026-7053, CVE-2026-7055, CVE-2026-7056, and CVE-2026-7057. The issues affect the /goform/L7Prot, /goform/VirtualSer, /goform/SafeUrlFilter, and /goform/setcfm endpoints respectively.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.