CVE-2026-3168Disclosure(tenda / f453)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromNatStaticSetting of the file /goform/NatStaticSetting of the component httpd. Executing a manipulation of the argument page can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f453
  • f453_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 5 mentions (2026-02-25); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
f453f453_firmware

2 versions affected across 2 products

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-02-25: 5Mentions · 2026-03-02: 1PoC Mentioned / Linked · 2026-02-25: 1Technical Details · 2026-02-25: 3Technical Details · 2026-03-02: 102-2503-02
Signal classification3 categories
Disclosure
350.0%
General
233.3%
PoC
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-255
Disclosure2General2PoC1
2026-03-021
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3168 (CVSS:7.4, HIGH) is Analyzed. A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromNatStaticSetting of the file /goform..https://nvd.nist.gov/vuln/detail/CVE-2026-3168 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-3168, noting a high‑severity weakness in Tenda F453 affecting the fromNatStaticSetting function, but provides no evidence of exploitation or mitigation.

    0000035
    173 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3168 Buffer Overflow Vulnerability in Tenda F453 Router via HTTP Request Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3168

    Post summary

    A buffer overflow vulnerability (CVE-2026-3168) has been disclosed for the Tenda F453 router, exploitable via HTTP request manipulation, with no PoC, exploit, or patch details provided.

    0000034
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3168 A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromNatStaticSetting of the file /goform/NatStaticSetting of the component httpd. Execut… https://www.cve.org/CVERecord?id=CVE-2026-3168

    Post summary

    The text briefly references CVE-2026-3168, noting a weakness in Tenda F453 firmware affecting a specific function, but provides no further details.

    0000089
    56.6K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-3168 - Tenda - F453 - https://www.redpacketsecurity.com/cve-alert-cve-2026-3168-tenda-f453/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3168 #tenda #f453

    Post summary

    The post announces a CVE alert for Tenda F453 (CVE-2026-3168) but provides no further technical or mitigation details.

    0000081
    3.5K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-3168** pertains to a critical security flaw in the **Tenda F453** router, specifically in the `fromNatStaticSetting` function located within the `/goform/NatStaticSetting` endpoint of the `httpd` component. The vulnerability arises from improper handling of user-supplied input in the `page` argument, leading to a **buffer overflow** condition. This flaw can be exploited remotely without user interaction, enabling an attacker to execute arbitrary code or cause a denial of service (DoS). #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #DDoS #BufferOverflow https://cvetodo.com/cve/CVE-2026-3168

    Post summary

    The post announces a critical buffer overflow vulnerability in the Tenda F453 router’s httpd component, detailing the affected function and potential remote exploitation.

    0000049
    20 followersView on X
  • CVEFind.com@CveFindCom
    PoC

    [CVE-2026-3168: HIGH] Vulnerability in Tenda F453 1.0.0.3 allows for remote buffer overflow attacks via manipulated arguments. Public exploit poses cyber security risk.#cve,CVE-2026-3168,#cybersecurity https://cvefind.com/CVE-2026-3168

    Post summary

    The post announces CVE-2026-3168, a high‑severity buffer overflow in Tenda F453, noting that a public exploit exists but no patch or detailed exploit code is provided.

    0000056
    584 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf453---
OStendaf453_firmware1.0.0.3--

Explore more