PT-2026-22247 · Tenda · Tenda F453
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda F453 version 1.0.0.3
Description
A buffer overflow issue exists in the
httpd component of the Tenda F453 router. The issue is located in the fromDhcpListClient function within the /goform/DhcpListClient API endpoint. Manipulation of the page parameter can trigger the overflow, potentially allowing remote attackers to execute arbitrary code or cause a denial-of-service condition. The exploit has been publicly disclosed.Recommendations
Update to a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider disabling the
httpd component until a patch is available.
Restrict access to the /goform/DhcpListClient API endpoint to minimize the risk of exploitation.
Avoid using the page parameter in the affected API endpoint until the issue is resolved.Exploit
Correção
DoS
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tenda F453