A vulnerability was found in Tenda F456 1.0.0.5. It has been classified as critical. This affects the function fromexeCommand of the file /goform/exeCommand. Performing a manipulation of the argument cmdinput results in stack-based buffer overflow.

This vulnerability is reported as CVE-2026-6196. The attack is possible to be carried out remotely. Moreover, an exploit is present.