PT-2026-22247 · Tenda · Tenda F453
Ltzhust
·
Published
2026-02-26
·
Updated
2026-03-04
·
CVE-2026-3272
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda F453 version 1.0.0.3
Description
A buffer overflow issue exists in the
httpd component of the Tenda F453 router. The issue is located in the fromDhcpListClient function within the /goform/DhcpListClient API endpoint. Manipulation of the page parameter can trigger the overflow, potentially allowing remote attackers to execute arbitrary code or cause a denial-of-service condition. The exploit has been publicly disclosed.Recommendations
Update to a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider disabling the
httpd component until a patch is available.
Restrict access to the /goform/DhcpListClient API endpoint to minimize the risk of exploitation.
Avoid using the page parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
DoS
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda F453