CVE-2026-3272Disclosure(tenda / f453)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. This manipulation of the argument page causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f453
  • f453_firmware

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-27); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
f453f453_firmware

2 versions affected across 2 products

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-27: 4Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Technical Details · 2026-02-27: 4Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 102-2703-0303-04
Signal classification1 categories
Disclosure
6100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-274
Disclosure4
2026-03-031
Disclosure1
2026-03-041
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3272 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/Dh..https://nvd.nist.gov/vuln/detail/CVE-2026-3272 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post reports a high‑severity vulnerability (CVE‑2026‑3272) in Tenda F453 firmware, detailing the affected function and file, but does not mention PoC, exploit, patch, or active exploitation.

    0000019
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3272 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/Dh..https://nvd.nist.gov/vuln/detail/CVE-2026-3272 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post reports CVE-2026-3272, a high‑severity vulnerability in Tenda F453 firmware affecting the fromDhcpListClient function, with CVSS 7.4, but no PoC, exploit, or patch details are provided.

    0000040
    173 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3272 A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. This manipu… https://www.cve.org/CVERecord?id=CVE-2026-3272 ----- Traducción: CVE-2026-3272 Se … http://infoflow.cloud`

    Post summary

    CVE-2026-3272 is a newly disclosed vulnerability affecting Tenda F453 1.0.0.3’s fromDhcpListClient function in httpd, with no evidence of a PoC, exploit, or patch available.

    0000030
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3272 A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. This manipu… https://www.cve.org/CVERecord?id=CVE-2026-3272

    Post summary

    CVE-2026-3272 has been identified in Tenda F453 1.0.0.3, affecting the fromDhcpListClient function in /goform/DhcpListClient component of httpd; no PoC, exploit, or patch details are provided.

    00000457
    56.6K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-3272** is a high-severity remote code execution vulnerability affecting the Tenda F453 router, specifically versions 1.0.0.3. The core issue resides in the `fromDhcpListClient` function within the `/goform/DhcpListClient` endpoint of the `httpd` component. An attacker can exploit this flaw by manipulating the `page` argument, leading to a buffer overflow condition. This allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS). #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #PrivilegeEscalation #DDoS https://cvetodo.com/cve/CVE-2026-3272

    Post summary

    High‑severity remote code execution vulnerability in Tenda F453 routers via a buffer overflow in the fromDhcpListClient function; the post contains technical details but no PoC, exploit code, patch, or evidence of active exploitation.

    0000041
    20 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3272: HIGH] Critical vulnerability found in Tenda F453 1.0.0.3 (httpd component). Buffer overflow via fromDhcpListClient function could lead to remote attacks. Stay vigilant!#cve,CVE-2026-3272,#cybersecurity https://cvefind.com/CVE-2026-3272

    Post summary

    The post announces a high‑severity buffer overflow in Tenda F453’s httpd component (via fromDhcpListClient) that could allow remote attacks, but it provides no PoC, exploit, patch, or evidence of active exploitation.

    0000052
    585 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf453---
OStendaf453_firmware1.0.0.3--

Explore more