CVE-2026-3274: Tenda F453 httpd L7Prot frmL7ProtForm buffer overflow
A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3274?
CVE-2026-3274 has been classified with a high severity due to the potential for remote code execution resulting from the buffer overflow.
How do I fix CVE-2026-3274?
To mitigate CVE-2026-3274, users should upgrade their Tenda F453 firmware to the latest version provided by Tenda.
Which devices are affected by CVE-2026-3274?
CVE-2026-3274 affects the Tenda F453 device running firmware version 1.0.0.3.
What kind of attack is possible due to CVE-2026-3274?
CVE-2026-3274 allows an attacker to exploit the buffer overflow vulnerability to execute arbitrary code on the affected device.
Is there a workaround for CVE-2026-3274?
Currently, the recommended solution for CVE-2026-3274 is to update the firmware, and no official workaround has been provided.