CVE-2026-3378

HIGH

Tenda F453 1.0.0.3 - Buffer Overflow

Title source: llm
STIX 2.1

Description

A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Executing a manipulation of the argument qos can lead to buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

Scores

CVSS v3 8.8
EPSS 0.0009
EPSS Percentile 25.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-119 CWE-120
Status published
Products (1)
tenda/f453_firmware 1.0.0.3
Published Mar 01, 2026
Tracked Since Mar 01, 2026