CVE-2026-3165: Tenda F453 httpd AdvSetWrlsafeset fromSetWifiGusetBasic buffer overflow
A vulnerability was determined in Tenda F453 1.0.0.3. Impacted is the function fromSetWifiGusetBasic of the file /goform/AdvSetWrlsafeset of the component httpd. This manipulation of the argument mitssid causes buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3165?
The severity of CVE-2026-3165 is considered high due to the potential for buffer overflow leading to remote code execution.
How do I fix CVE-2026-3165?
To fix CVE-2026-3165, update the Tenda F453 firmware to the latest version provided by Tenda that addresses the vulnerability.
What is Tenda F453 vulnerability CVE-2026-3165 related to?
CVE-2026-3165 is related to a buffer overflow vulnerability in the fromSetWifiGusetBasic function of the httpd component in Tenda F453.
What impact can CVE-2026-3165 have on my device?
CVE-2026-3165 can lead to unauthorized access and potential execution of arbitrary code, compromising the device's security.
Is there a workaround for CVE-2026-3165 if I cannot update?
While the best solution is to update the firmware, if you cannot do so, consider disabling remote management features to mitigate the risk.