CVE-2026-6199 is a stack-based buffer overflow vulnerability discovered in Tenda F456 router firmware version 1.0.0.5, specifically in the qossetting function of the /goform/qossetting endpoint. The flaw exists in the page parameter handling and affects the quality-of-service configuration functionality of the device. The vulnerability carries a HIGH severity rating with a CVSS score of 8.8, as it requires only low attack complexity and low privileges to exploit remotely, with no user interaction needed. Successful exploitation could allow an authenticated attacker to achieve complete system compromise, including high-impact confidentiality, integrity, and availability breaches on affected routers. The exploit code has been publicly released, elevating operational risk. However, the vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows minimal exploitation activity as indicated by the low EPSS score of 0.000480. Community attention remains limited given the moderate FAUCET risk score of 51.0, suggesting this is a lower-priority concern compared to more actively targeted vulnerabilities, though patching should still be prioritized for exposed Tenda F456 devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Tenda | F456 | 1.0.0.5CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.