Tenda
Tenda F453 Firmware: vulnerabilities and CVEs
Tenda F453 Firmware has 30 published vulnerabilities, 30 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs30
Last 12 months30
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6989 | Low (2.1) | 6.3% | — | Apr 25, 2026 | A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injection. It is possible… |
| CVE-2026-5021 | High (7.4) | 1.0% | — | Mar 29, 2026 | A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the component httpd. This manipulation of the argument delno causes stack-based buffer… |
| CVE-2026-4554 | Low (2.1) | 6.5% | — | Mar 22, 2026 | A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac results in command injection. It is… |
| CVE-2026-4553 | High (7.4) | 1.0% | — | Mar 22, 2026 | A vulnerability was identified in Tenda F453 1.0.0.3. Impacted is the function fromNatlimit of the file /goform/Natlimit of the component Parameters Handler. The manipulation of the argument page leads to stack-based… |
| CVE-2026-4552 | High (7.4) | 1.0% | — | Mar 22, 2026 | A vulnerability was determined in Tenda F453 1.0.0.3. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component Parameters Handler. Executing a manipulation of the argument page can… |
| CVE-2026-4551 | High (7.4) | 1.0% | — | Mar 22, 2026 | A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeClientFilter of the component Parameters Handler. Performing a manipulation of the… |
| CVE-2026-3769 | High (7.4) | 1.0% | — | Mar 8, 2026 | A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function WrlclientSet of the file /goform/WrlclientSet. The manipulation of the argument GO results in stack-based buffer overflow. The… |
| CVE-2026-3768 | High (7.4) | 1.0% | — | Mar 8, 2026 | A security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet. The manipulation of the argument GO leads to stack-based… |
| CVE-2026-3732 | High (7.4) | 1.0% | — | Mar 8, 2026 | A security vulnerability has been detected in Tenda F453 1.0.0.3. This affects the function strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. It is… |
| CVE-2026-3729 | High (7.4) | 1.0% | — | Mar 8, 2026 | A vulnerability was identified in Tenda F453 1.0.0.3/3.As. Impacted is the function fromPptpUserAdd of the file /goform/PPTPDClient. Such manipulation of the argument username/opttype leads to stack-based buffer… |
| CVE-2026-3728 | High (7.4) | 1.0% | — | Mar 8, 2026 | A vulnerability was determined in Tenda F453 1.0.0.3/1.If. This issue affects the function fromSetCfm of the file /goform/setcfm. This manipulation of the argument funcname/funcpara1 causes stack-based buffer overflow.… |
| CVE-2026-3727 | High (7.4) | 1.0% | — | Mar 8, 2026 | A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function sub_3C6C0 of the file /goform/QuickIndex. The manipulation of the argument mit_linktype/PPPOEPassword results in stack-based… |
| CVE-2026-3726 | High (7.4) | 1.0% | — | Mar 8, 2026 | A vulnerability has been found in Tenda F453 1.0.0.3. This affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the argument page leads to stack-based buffer… |
| CVE-2026-3399 | High (7.4) | 1.0% | — | Mar 1, 2026 | A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. The manipulation of the argument dips… |
| CVE-2026-3398 | High (7.4) | 1.0% | — | Mar 1, 2026 | A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a manipulation of the argument wanmode/PPPOEPassword can lead… |
| CVE-2026-3380 | High (7.4) | 1.0% | — | Mar 1, 2026 | A vulnerability was found in Tenda F453 1.0.0.3. This issue affects the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argument page results in buffer overflow. The attack may be launched… |
| CVE-2026-3379 | High (7.4) | 1.0% | — | Mar 1, 2026 | A vulnerability has been found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page leads to buffer overflow. The attack may… |
| CVE-2026-3378 | High (7.4) | 1.0% | — | Mar 1, 2026 | A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Executing a manipulation of the argument qos can lead to buffer overflow. The attack can be launched… |
| CVE-2026-3377 | High (7.4) | 1.0% | — | Mar 1, 2026 | A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Performing a manipulation of the argument page results in buffer overflow.… |
| CVE-2026-3376 | High (7.4) | 1.0% | — | Feb 28, 2026 | A security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromSafeMacFilter of the file /goform/SafeMacFilter. Such manipulation of the argument page leads to… |
| CVE-2026-3275 | High (7.4) | 1.0% | — | Feb 27, 2026 | A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addressNat of the component httpd. Executing a manipulation of the argument entrys can lead to buffer… |
| CVE-2026-3274 | High (7.4) | 1.0% | — | Feb 27, 2026 | A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results… |
| CVE-2026-3273 | High (7.4) | 1.0% | — | Feb 27, 2026 | A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component httpd. Such manipulation of the argument… |
| CVE-2026-3272 | High (7.4) | 1.0% | — | Feb 27, 2026 | A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. This manipulation of the argument page causes buffer overflow.… |
| CVE-2026-3271 | High (7.4) | 1.1% | — | Feb 27, 2026 | A vulnerability was found in Tenda F453 1.0.0.3. This impacts the function fromP2pListFilter of the file /goform/P2pListFilterof of the component httpd. The manipulation of the argument page results in buffer overflow.… |
| CVE-2026-3169 | High (7.4) | 1.0% | — | Feb 25, 2026 | A security vulnerability has been detected in Tenda F453 1.0.0.3. This impacts the function fromSafeEmailFilter of the file /goform/SafeEmailFilter of the component httpd. The manipulation of the argument page leads to… |
| CVE-2026-3168 | High (7.4) | 1.0% | — | Feb 25, 2026 | A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromNatStaticSetting of the file /goform/NatStaticSetting of the component httpd. Executing a manipulation of the argument page can lead to… |
| CVE-2026-3167 | High (7.4) | 1.0% | — | Feb 25, 2026 | A security flaw has been discovered in Tenda F453 1.0.0.3. The impacted element is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component httpd. Performing a manipulation of the argument… |
| CVE-2026-3166 | High (7.4) | 1.0% | — | Feb 25, 2026 | A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /goform/RouteStatic of the component httpd. Such manipulation of the argument page leads to buffer… |
| CVE-2026-3165 | High (7.4) | 1.0% | — | Feb 25, 2026 | A vulnerability was determined in Tenda F453 1.0.0.3. Impacted is the function fromSetWifiGusetBasic of the file /goform/AdvSetWrlsafeset of the component httpd. This manipulation of the argument mit_ssid causes buffer… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.