Description
A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a manipulation of the argument wanmode/PPPOEPassword can lead to buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
Timeline
| 2026-03-01: | Advisory disclosed |
| 2026-03-01: | VulDB entry created |
| 2026-03-01: | VulDB entry last update |
Credits
LtzHust2 (VulDB User)
References
vuldb.com/?id.348293 (VDB-348293 | Tenda F453 httpd AdvSetWan fromAdvSetWan buffer overflow)
vuldb.com/?ctiid.348293 (VDB-348293 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.759630 (Submit #759630 | Tenda F453 v1.0.0.3 Buffer Access Using Size of Source Buffer)
github.com/...ngzheng/vul_db/blob/main/F453/vul_82/README.md
www.tenda.com.cn/