Severity
7.4HIGH
EPSS
0.1%
top 71.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25

Description

A security flaw has been discovered in Tenda F453 1.0.0.3. The impacted element is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component httpd. Performing a manipulation of the argument webSiteId results in buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5tenda/f4531.0.0.3
NVDtenda/f453_firmware1.0.0.3

🔴Vulnerability Details

2
GHSA
GHSA-xcq6-x53r-q98g: A security flaw has been discovered in Tenda F453 12026-02-25
CVEList
Tenda F453 httpd webtypelibrary formWebTypeLibrary buffer overflow2026-02-25