CVE-2026-3678: Tenda FH451 AdvSetWan sub_3C434 stack-based overflow
A vulnerability was determined in Tenda FH451 1.0.0.9. Affected is the function sub3C434 of the file /goform/AdvSetWan. This manipulation of the argument wanmode/PPPOEPassword causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3678?
CVE-2026-3678 has a high severity rating due to the potential for remote code execution via stack-based buffer overflow.
How do I fix CVE-2026-3678?
To fix CVE-2026-3678, update the Tenda FH451 firmware to the latest version that addresses this vulnerability.
What kind of attack can exploit CVE-2026-3678?
CVE-2026-3678 can be exploited by an attacker sending specially crafted input to the affected function, leading to a stack-based overflow.
Which devices are affected by CVE-2026-3678?
CVE-2026-3678 specifically affects the Tenda FH451 router with firmware version 1.0.0.9.
Is CVE-2026-3678 being actively exploited in the wild?
As of now, there are no specific reports indicating that CVE-2026-3678 is being actively exploited in the wild.