CVE-2026-3274Improper Restriction of Operations within the Bounds of a Memory Buffer in F453

Severity
7.4HIGHNVD
EPSS
0.1%
top 74.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27

Description

A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5tenda/f4531.0.0.3
NVDtenda/f453_firmware1.0.0.3

🔴Vulnerability Details

2
CVEList
Tenda F453 httpd L7Prot frmL7ProtForm buffer overflow2026-02-27
GHSA
GHSA-pcpr-68v2-x3jj: A security flaw has been discovered in Tenda F453 12026-02-27
CVE-2026-3274 — Tenda F453 vulnerability | cvebase