CVE-2026-3729: Tenda F453 PPTPDClient fromPptpUserAdd stack-based overflow
A vulnerability was identified in Tenda F453 1.0.0.3/3.As. Impacted is the function fromPptpUserAdd of the file /goform/PPTPDClient. Such manipulation of the argument username/opttype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3729?
CVE-2026-3729 is classified as a high severity vulnerability due to the potential for stack-based buffer overflow, which can lead to remote code execution.
How do I fix CVE-2026-3729?
To fix CVE-2026-3729, update the Tenda F453 firmware to the latest version provided by the vendor.
What does the CVE-2026-3729 vulnerability affect?
CVE-2026-3729 specifically affects the Tenda F453 device's PPTPDClient functionality.
What will happen if I am affected by CVE-2026-3729?
If affected by CVE-2026-3729, an attacker could exploit the vulnerability to execute arbitrary code on the device.
Is there a workaround for CVE-2026-3729?
Currently, the best workaround for CVE-2026-3729 is to disable PPTP if it is not needed until a fix is applied.