« Back to list

Tenda

Tenda F453 Firmware: vulnerabilities and CVEs

Tenda F453 Firmware has 30 published vulnerabilities, 30 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs30
Last 12 months30
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-6989Low (2.1)6.3%—Apr 25, 2026
A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injection. It is possible…
CVE-2026-5021High (7.4)1.0%—Mar 29, 2026
A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the component httpd. This manipulation of the argument delno causes stack-based buffer…
CVE-2026-4554Low (2.1)6.5%—Mar 22, 2026
A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac results in command injection. It is…
CVE-2026-4553High (7.4)1.0%—Mar 22, 2026
A vulnerability was identified in Tenda F453 1.0.0.3. Impacted is the function fromNatlimit of the file /goform/Natlimit of the component Parameters Handler. The manipulation of the argument page leads to stack-based…
CVE-2026-4552High (7.4)1.0%—Mar 22, 2026
A vulnerability was determined in Tenda F453 1.0.0.3. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component Parameters Handler. Executing a manipulation of the argument page can…
CVE-2026-4551High (7.4)1.0%—Mar 22, 2026
A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeClientFilter of the component Parameters Handler. Performing a manipulation of the…
CVE-2026-3769High (7.4)1.0%—Mar 8, 2026
A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function WrlclientSet of the file /goform/WrlclientSet. The manipulation of the argument GO results in stack-based buffer overflow. The…
CVE-2026-3768High (7.4)1.0%—Mar 8, 2026
A security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet. The manipulation of the argument GO leads to stack-based…
CVE-2026-3732High (7.4)1.0%—Mar 8, 2026
A security vulnerability has been detected in Tenda F453 1.0.0.3. This affects the function strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. It is…
CVE-2026-3729High (7.4)1.0%—Mar 8, 2026
A vulnerability was identified in Tenda F453 1.0.0.3/3.As. Impacted is the function fromPptpUserAdd of the file /goform/PPTPDClient. Such manipulation of the argument username/opttype leads to stack-based buffer…
CVE-2026-3728High (7.4)1.0%—Mar 8, 2026
A vulnerability was determined in Tenda F453 1.0.0.3/1.If. This issue affects the function fromSetCfm of the file /goform/setcfm. This manipulation of the argument funcname/funcpara1 causes stack-based buffer overflow.…
CVE-2026-3727High (7.4)1.0%—Mar 8, 2026
A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function sub_3C6C0 of the file /goform/QuickIndex. The manipulation of the argument mit_linktype/PPPOEPassword results in stack-based…
CVE-2026-3726High (7.4)1.0%—Mar 8, 2026
A vulnerability has been found in Tenda F453 1.0.0.3. This affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the argument page leads to stack-based buffer…
CVE-2026-3399High (7.4)1.0%—Mar 1, 2026
A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. The manipulation of the argument dips…
CVE-2026-3398High (7.4)1.0%—Mar 1, 2026
A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a manipulation of the argument wanmode/PPPOEPassword can lead…
CVE-2026-3380High (7.4)1.0%—Mar 1, 2026
A vulnerability was found in Tenda F453 1.0.0.3. This issue affects the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argument page results in buffer overflow. The attack may be launched…
CVE-2026-3379High (7.4)1.0%—Mar 1, 2026
A vulnerability has been found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page leads to buffer overflow. The attack may…
CVE-2026-3378High (7.4)1.0%—Mar 1, 2026
A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Executing a manipulation of the argument qos can lead to buffer overflow. The attack can be launched…
CVE-2026-3377High (7.4)1.0%—Mar 1, 2026
A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Performing a manipulation of the argument page results in buffer overflow.…
CVE-2026-3376High (7.4)1.0%—Feb 28, 2026
A security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromSafeMacFilter of the file /goform/SafeMacFilter. Such manipulation of the argument page leads to…
CVE-2026-3275High (7.4)1.0%—Feb 27, 2026
A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addressNat of the component httpd. Executing a manipulation of the argument entrys can lead to buffer…
CVE-2026-3274High (7.4)1.0%—Feb 27, 2026
A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results…
CVE-2026-3273High (7.4)1.0%—Feb 27, 2026
A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component httpd. Such manipulation of the argument…
CVE-2026-3272High (7.4)1.0%—Feb 27, 2026
A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. This manipulation of the argument page causes buffer overflow.…
CVE-2026-3271High (7.4)1.1%—Feb 27, 2026
A vulnerability was found in Tenda F453 1.0.0.3. This impacts the function fromP2pListFilter of the file /goform/P2pListFilterof of the component httpd. The manipulation of the argument page results in buffer overflow.…
CVE-2026-3169High (7.4)1.0%—Feb 25, 2026
A security vulnerability has been detected in Tenda F453 1.0.0.3. This impacts the function fromSafeEmailFilter of the file /goform/SafeEmailFilter of the component httpd. The manipulation of the argument page leads to…
CVE-2026-3168High (7.4)1.0%—Feb 25, 2026
A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromNatStaticSetting of the file /goform/NatStaticSetting of the component httpd. Executing a manipulation of the argument page can lead to…
CVE-2026-3167High (7.4)1.0%—Feb 25, 2026
A security flaw has been discovered in Tenda F453 1.0.0.3. The impacted element is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component httpd. Performing a manipulation of the argument…
CVE-2026-3166High (7.4)1.0%—Feb 25, 2026
A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /goform/RouteStatic of the component httpd. Such manipulation of the argument page leads to buffer…
CVE-2026-3165High (7.4)1.0%—Feb 25, 2026
A vulnerability was determined in Tenda F453 1.0.0.3. Impacted is the function fromSetWifiGusetBasic of the file /goform/AdvSetWrlsafeset of the component httpd. This manipulation of the argument mit_ssid causes buffer…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter28
  2. T1210 Exploitation of Remote Services28

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Tenda