CVE-2026-3398

HIGH

Tenda F453 1.0.0.3 - Buffer Overflow

Title source: llm

Description

A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a manipulation of the argument wanmode/PPPOEPassword can lead to buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

Scores

CVSS v3 8.8
EPSS 0.0008
EPSS Percentile 23.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-119 CWE-120
Status published

Affected Products (1)

tenda/f453_firmware

Timeline

Published Mar 01, 2026
Tracked Since Mar 02, 2026