CVE-2026-5021: Tenda F453 httpd PPTPUserSetting fromPPTPUserSetting stack-based overflow
A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the component httpd. This manipulation of the argument delno causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5021?
CVE-2026-5021 is classified as a high severity vulnerability due to the stack-based buffer overflow it can cause.
How do I fix CVE-2026-5021?
To fix CVE-2026-5021, update the Tenda F453 firmware to the latest version provided by the manufacturer.
Which versions are affected by CVE-2026-5021?
CVE-2026-5021 specifically affects Tenda F453 version 1.0.0.3.
What is the impact of CVE-2026-5021?
The impact of CVE-2026-5021 is that it may allow remote code execution or system compromise due to the stack-based overflow.
How does the CVE-2026-5021 vulnerability occur?
CVE-2026-5021 occurs due to improper handling of arguments in the fromPPTPUserSetting function within the httpd component.