PT-2026-23937 · Tenda · Tenda F453

Ltzhust

·

Published

2026-02-04

·

Updated

2026-03-13

·

CVE-2026-3732

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda F453 version 1.0.0.3
Description A stack-based buffer overflow exists in the strcpy function within the /goform/exeCommand file of the Tenda F453 router. The issue is triggered by manipulating the cmdinput argument, potentially allowing for remote code execution and device takeover. The exploit for this issue has been publicly disclosed. The vulnerability affects the network-accessible management interface and can be exploited remotely with a crafted cmdinput parameter.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the /goform/exeCommand endpoint to minimize the risk of exploitation.

Exploit

Fix

RCE

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-06155
CVE-2026-3732

Affected Products

Tenda F453