CVE-2026-3166Disclosure(tenda / f453)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /goform/RouteStatic of the component httpd. Such manipulation of the argument page leads to buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be used.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f453
  • f453_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Exploit: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-02-25); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
f453f453_firmware

2 versions affected across 2 products

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-02-25: 5Mentions · 2026-03-02: 1PoC Mentioned / Linked · 2026-02-25: 1Technical Details · 2026-02-25: 3Technical Details · 2026-03-02: 102-2503-02
Signal classification2 categories
Disclosure
583.3%
Exploit
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-255
Disclosure4Exploit1
2026-03-021
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3166 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /..https://nvd.nist.gov/vuln/detail/CVE-2026-3166 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-3166, noting its CVSS score and the affected function in Tenda F453 firmware, but provides no evidence of exploitation or mitigation.

    0000038
    173 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3166 Tenda F453 Remote Buffer Overflow in RouteStatic Handling Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3166

    Post summary

    A remote buffer overflow vulnerability (CVE-2026-3166) has been identified in the Tenda F453's RouteStatic handling function, with no additional details on exploitation or mitigation provided.

    0000026
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3166 A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /goform/RouteStatic of the component httpd. Such … https://www.cve.org/CVERecord?id=CVE-2026-3166

    Post summary

    A CVE‑2026‑3166 vulnerability was identified in Tenda F453 firmware, affecting the fromRouteStatic function in the httpd component, but no further technical details or mitigation information are provided.

    0000094
    56.6K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3166 - Tenda - F453 - https://www.redpacketsecurity.com/cve-alert-cve-2026-3166-tenda-f453/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3166 #tenda #f453

    Post summary

    A CVE alert for CVE-2026-3166 affecting Tenda F453 was posted, but no further details such as PoC, exploit, patch, or technical specifics were provided.

    0000073
    3.5K followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-3166: HIGH] Critical cyber security alert: Vulnerability in Tenda F453 1.0.0.3 allows remote buffer overflow attacks via manipulation of /goform/RouteStatic function. Exploit publicly available.#cve,CVE-2026-3166,#cybersecurity https://cvefind.com/CVE-2026-3166

    Post summary

    A critical buffer overflow vulnerability (CVE-2026-3166) in Tenda F453 routers allows remote attacks; an exploit is publicly available, but no patch or active exploitation reports are mentioned.

    0000060
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-3166** is a high-severity remote code execution vulnerability affecting the **Tenda F453** router, specifically version **1.0.0.3**. The flaw resides within the `fromRouteStatic` function located in the `/goform/RouteStatic` endpoint of the device's embedded HTTP server (`httpd`). An attacker can exploit this vulnerability by manipulating the `page` argument in the HTTP request, leading to a buffer overflow condition. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #BufferOverflow https://cvetodo.com/cve/CVE-2026-3166

    Post summary

    The post announces a high‑severity remote code execution vulnerability in the Tenda F453 router, detailing the affected function, endpoint, and exploit vector, but does not provide a PoC, exploit code, or patch information.

    0000045
    20 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf453---
OStendaf453_firmware1.0.0.3--

Explore more