CVE-2026-3167: Tenda F453 httpd webtypelibrary formWebTypeLibrary buffer overflow
A security flaw has been discovered in Tenda F453 1.0.0.3. The impacted element is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component httpd. Performing a manipulation of the argument webSiteId results in buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3167?
CVE-2026-3167 is classified as a high severity vulnerability due to its potential to cause a buffer overflow.
How do I fix CVE-2026-3167?
To mitigate CVE-2026-3167, it is recommended to update the Tenda F453 firmware to the latest version provided by the vendor.
What does CVE-2026-3167 affect?
CVE-2026-3167 affects the Tenda F453 device, specifically impacting the httpd service's formWebTypeLibrary function.
What kind of attack is possible with CVE-2026-3167?
CVE-2026-3167 allows an attacker to exploit a buffer overflow, potentially leading to remote code execution.
When was CVE-2026-3167 disclosed?
CVE-2026-3167 was disclosed in the year 2026.