CVE-2026-3732: Tenda F453 exeCommand strcpy stack-based overflow
A security vulnerability has been detected in Tenda F453 1.0.0.3. This affects the function strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3732?
CVE-2026-3732 is considered a critical vulnerability due to the potential for remote code execution via stack-based buffer overflow.
How do I fix CVE-2026-3732?
To fix CVE-2026-3732, update the Tenda F453 router to the latest firmware version provided by the manufacturer.
What is the nature of the vulnerability in CVE-2026-3732?
CVE-2026-3732 involves a stack-based buffer overflow caused by improper handling of the cmdinput argument in the strcpy function.
Which devices are affected by CVE-2026-3732?
CVE-2026-3732 specifically affects Tenda F453 devices running version 1.0.0.3.
Can CVE-2026-3732 lead to unauthorized access?
Yes, if exploited, CVE-2026-3732 can allow attackers to execute arbitrary commands on the affected Tenda F453 device.