Description
A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Executing a manipulation of the argument qos can lead to buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
Problem types
Product status
Timeline
| 2026-02-28: | Advisory disclosed |
| 2026-02-28: | VulDB entry created |
| 2026-02-28: | VulDB entry last update |
Credits
LtzHust2 (VulDB User)
References
vuldb.com/?id.348263 (VDB-348263 | Tenda F453 qossetting fromqossetting buffer overflow)
vuldb.com/?ctiid.348263 (VDB-348263 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.759625 (Submit #759625 | Tenda F453 v1.0.0.3 Buffer Access Using Size of Source Buffer)
github.com/...ngzheng/vul_db/blob/main/F453/vul_78/README.md
www.tenda.com.cn/