CVE-2026-4554Injection in F453

Severity
5.3MEDIUMNVD
EPSS
0.8%
top 25.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 22

Description

A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5tenda/f4531.0.0.3
NVDtenda/f453_firmware1.0.0.3

🔴Vulnerability Details

2
GHSA
GHSA-gh64-hffv-c24x: A security flaw has been discovered in Tenda F453 12026-03-22
CVEList
Tenda F453 WriteFacMac FormWriteFacMac privilege escalation2026-03-22
CVE-2026-4554 — Injection in Tenda F453 | cvebase