CVE-2026-7080
published 2026-04-27CVE-2026-7080: A security vulnerability has been detected in Tenda F456 1.0.0.5. This impacts the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the…
PriorityP264high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.64%
46.5th percentile
A security vulnerability has been detected in Tenda F456 1.0.0.5. This impacts the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the component httpd. Such manipulation of the argument delno leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | f456 | — | — |
| tenda | f456_firmware | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-1528 undici: undici: Denial of Service via crafted WebSocket frame with large length
bugzilla·2026-03-12·CVSS 7.5
CVE-2026-1528 [HIGH] CVE-2026-1528 undici: undici: Denial of Service via crafted WebSocket frame with large length
CVE-2026-1528 undici: undici: Denial of Service via crafted WebSocket frame with large length
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.
Patches
Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:7080 https://access.redhat.com/errata/RHSA-2026:7080
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2026:7123 https://access.redhat.com/errata/RHSA-2026:7123
---
This issue has been addr
Bugzilla
CVE-2026-25547 brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion
bugzilla·2026-02-04·CVSS 9.2
CVE-2026-25547 [CRITICAL] CVE-2026-25547 brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion
CVE-2026-25547 brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion
@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process. This issue has been patched in version 5.0.1.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:7080 https://access.
2026-04-27
Published