CVE-2026-3398: Tenda F453 httpd AdvSetWan fromAdvSetWan buffer overflow
A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a manipulation of the argument wanmode/PPPOEPassword can lead to buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3398?
CVE-2026-3398 is classified with a high severity due to its potential to allow remote attackers to execute arbitrary code through a buffer overflow.
How do I fix CVE-2026-3398?
To fix CVE-2026-3398, update the Tenda F453 device firmware to the latest version that addresses this vulnerability.
What is affected by CVE-2026-3398?
CVE-2026-3398 affects the Tenda F453 device running version 1.0.0.3 and specifically impacts the function fromAdvSetWan.
What could happen if CVE-2026-3398 is exploited?
If exploited, CVE-2026-3398 could allow an attacker to gain unauthorized access or control over the affected device.
How can I determine if my device is vulnerable to CVE-2026-3398?
To determine if your device is vulnerable to CVE-2026-3398, check if it is a Tenda F453 running version 1.0.0.3 and evaluate its firmware against the latest security advisories.