CVE-2026-3166: Tenda F453 httpd RouteStatic fromRouteStatic buffer overflow
A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /goform/RouteStatic of the component httpd. Such manipulation of the argument page leads to buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3166?
CVE-2026-3166 is categorized as a high severity vulnerability due to the potential for remote code execution through buffer overflow.
How do I fix CVE-2026-3166?
To mitigate CVE-2026-3166, users should update the Tenda F453 firmware to the latest version provided by the manufacturer.
What impact does CVE-2026-3166 have on Tenda F453 devices?
CVE-2026-3166 could allow an attacker to execute arbitrary code on Tenda F453 devices, compromising their security.
What versions of Tenda F453 are affected by CVE-2026-3166?
CVE-2026-3166 affects Tenda F453 devices running version 1.0.0.3.
Can CVE-2026-3166 be exploited remotely?
Yes, CVE-2026-3166 can be exploited remotely, allowing unauthorized access to affected devices.