CVE-2026-3677: Tenda FH451 setcfm fromSetCfm stack-based overflow
A vulnerability was found in Tenda FH451 1.0.0.9. This impacts the function fromSetCfm of the file /goform/setcfm. The manipulation of the argument funcname/funcpara1 results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3677?
CVE-2026-3677 has a high severity due to its potential for remote exploitation leading to stack-based buffer overflow.
How do I fix CVE-2026-3677?
To mitigate CVE-2026-3677, users should update their Tenda FH451 firmware to the latest version provided by the vendor.
What are the potential impacts of CVE-2026-3677?
The potential impacts of CVE-2026-3677 include unauthorized access and execution of arbitrary code on the affected device.
Which devices are affected by CVE-2026-3677?
CVE-2026-3677 specifically affects the Tenda FH451 running version 1.0.0.9.
Can CVE-2026-3677 be exploited remotely?
Yes, CVE-2026-3677 can be exploited remotely by manipulating specific arguments in the affected function.