CVE-2026-3274Disclosure(tenda / f453)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f453
  • f453_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 5 mentions (2026-02-27); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
f453f453_firmware

2 versions affected across 2 products

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-02-27: 5Mentions · 2026-03-04: 1PoC Mentioned / Linked · 2026-02-27: 1Technical Details · 2026-02-27: 3Technical Details · 2026-03-04: 102-2703-04
Signal classification2 categories
Disclosure
583.3%
PoC
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-275
Disclosure4PoC1
2026-03-041
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3274 (CVSS:7.4, HIGH) is Analyzed. A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the f..https://nvd.nist.gov/vuln/detail/CVE-2026-3274 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A high‑severity vulnerability (CVSS 7.4) was identified in the Tenda F453 router’s frmL7ProtForm function, with no PoC, exploit, or patch details provided.

    0000023
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3274 A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Perfo… https://www.cve.org/CVERecord?id=CVE-2026-3274

    Post summary

    The post announces the discovery of CVE-2026-3274 in the Tenda F453 firmware, noting the affected function and file, but provides no details on exploitation, patching, or PoC.

    00000114
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3274 Buffer Overflow in Tenda F453 Router via Remote Page Argument Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3274

    Post summary

    The post announces a buffer overflow vulnerability in the Tenda F453 router (CVE-2026-3274), providing limited technical details but no evidence of exploitation or patch availability.

    0000038
    4.0K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3274 - Tenda - F453 - https://www.redpacketsecurity.com/cve-alert-cve-2026-3274-tenda-f453/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3274 #tenda #f453

    Post summary

    The tweet announces CVE-2026-3274 for Tenda F453 and provides a link for more information, but offers no technical details, exploitation evidence, or mitigation steps.

    0000083
    3.5K followersView on X
  • CVEFind.com@CveFindCom
    PoC

    [CVE-2026-3274: HIGH] Security flaw found in Tenda F453 1.0.0.3 allows remote buffer overflow attack through manipulation of argument page in httpd component, exploit already public.#cve,CVE-2026-3274,#cybersecurity https://cvefind.com/CVE-2026-3274

    Post summary

    A high‑severity buffer overflow flaw in the Tenda F453 router has been disclosed, with an exploit already publicly available, but no patch or mitigation details are provided.

    0000064
    585 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-3274** pertains to a buffer overflow vulnerability in the Tenda F453 router, specifically affecting the `frmL7ProtForm` function within the `/goform/L7Prot` endpoint of the `httpd` component. An attacker can exploit this flaw remotely by manipulating the `page` argument in HTTP requests, leading to a buffer overflow condition. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #DDoS #BufferOverflow https://cvetodo.com/cve/CVE-2026-3274

    Post summary

    CVE-2026-3274 is a buffer overflow vulnerability in the Tenda F453 router’s `frmL7ProtForm` function (within the `/goform/L7Prot` HTTP endpoint), allowing remote attackers to exploit via the `page` argument.

    0000043
    20 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf453---
OStendaf453_firmware1.0.0.3--

Explore more