PT-2026-22247 · Tenda · Tenda F453

Ltzhust

·

Published

2026-02-26

·

Updated

2026-03-04

·

CVE-2026-3272

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda F453 version 1.0.0.3
Description A buffer overflow issue exists in the httpd component of the Tenda F453 router. The issue is located in the fromDhcpListClient function within the /goform/DhcpListClient API endpoint. Manipulation of the page parameter can trigger the overflow, potentially allowing remote attackers to execute arbitrary code or cause a denial-of-service condition. The exploit has been publicly disclosed.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the httpd component until a patch is available. Restrict access to the /goform/DhcpListClient API endpoint to minimize the risk of exploitation. Avoid using the page parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

DoS

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-02300
CVE-2026-3272

Affected Products

Tenda F453