CVE-2026-3728: Tenda F453 setcfm fromSetCfm stack-based overflow
A vulnerability was determined in Tenda F453 1.0.0.3/1.If. This issue affects the function fromSetCfm of the file /goform/setcfm. This manipulation of the argument funcname/funcpara1 causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3728?
CVE-2026-3728 has a high severity due to the potential for remote exploitation through a stack-based buffer overflow.
How do I fix CVE-2026-3728?
To fix CVE-2026-3728, update the Tenda F453 firmware to the latest version provided by the vendor.
What is the impact of CVE-2026-3728?
The impact of CVE-2026-3728 includes the potential for remote code execution, which can compromise the security of the affected device.
Who is affected by CVE-2026-3728?
CVE-2026-3728 affects users of the Tenda F453 device running firmware versions 1.0.0.3 and 1.If.
How was CVE-2026-3728 discovered?
CVE-2026-3728 was discovered during a security assessment revealing the vulnerability in the fromSetCfm function.