CVE-2026-3168: Tenda F453 httpd NatStaticSetting fromNatStaticSetting buffer overflow
A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromNatStaticSetting of the file /goform/NatStaticSetting of the component httpd. Executing a manipulation of the argument page can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3168?
CVE-2026-3168 is classified as a critical vulnerability due to its potential for remote code execution through a buffer overflow.
How do I fix CVE-2026-3168?
To fix CVE-2026-3168, update the Tenda F453 firmware to the latest available version that addresses this vulnerability.
What devices are affected by CVE-2026-3168?
CVE-2026-3168 specifically affects the Tenda F453 router running version 1.0.0.3.
What are the potential consequences of CVE-2026-3168?
Exploiting CVE-2026-3168 can lead to unauthorized access and control of the affected device.
How is CVE-2026-3168 exploited?
CVE-2026-3168 can be exploited by manipulating arguments sent to the fromNatStaticSetting function in the HTTP daemon.