Stack-Based Buffer Overflow in Tenda F453 Router
CVE-2026-3726
Key Information:
Badges
What is CVE-2026-3726?
A vulnerability exists in the Tenda F453 router, specifically in the fromwebExcptypemanFilter function located in /goform/webExcptypemanFilter. This issue is triggered by improper handling of the 'page' argument, which can lead to a stack-based buffer overflow. This condition allows an attacker to execute arbitrary code remotely, posing significant security risks. Public disclosure of this exploit means that successful attacks may occur if proper mitigation strategies are not implemented.
Affected Version(s)
F453 1.0.0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved