A vulnerability, which was classified as critical, was found in Tenda F456 1.0.0.5. This impacts the function
FromWriteFacMac of the file /goform/WriteFacMac of the component httpd. The manipulation of the argument mac results in command injection.
This vulnerability is identified as CVE-2026-7102. The attack can be executed remotely. Additionally, an exploit exists.