CVE-2026-3275Disclosure(tenda / f453)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addressNat of the component httpd. Executing a manipulation of the argument entrys can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f453
  • f453_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Exploit: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-02-27); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
f453f453_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-27: 4Mentions · 2026-03-04: 1PoC Mentioned / Linked · 2026-02-27: 1Technical Details · 2026-02-27: 4Technical Details · 2026-03-04: 102-2703-04
Signal classification3 categories
Disclosure
360.0%
Exploit
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-274
Disclosure2Exploit1General1
2026-03-041
Disclosure1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3275 (CVSS:7.4, HIGH) is Analyzed. A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addre..https://nvd.nist.gov/vuln/detail/CVE-2026-3275 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-3275, a high‑severity flaw in Tenda F453 firmware affecting the fromAddressNat function, with CVSS 7.4, but no PoC, exploit, or patch details are provided.

    0000022
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3275 A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addressNat of the component httpd. Executing a manipu… https://www.cve.org/CVERecord?id=CVE-2026-3275

    Post summary

    A weakness has been identified in the Tenda F453 firmware affecting the fromAddressNat function of the httpd component, with technical details provided but no exploit or patch information.

    00000128
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-3275: HIGH] Critical vulnerability discovered in Tenda F453 1.0.0.3 allows remote cyber attacks through buffer overflow. Public exploit available, posing a severe risk.#cve,CVE-2026-3275,#cybersecurity https://cvefind.com/CVE-2026-3275

    Post summary

    The post announces a high‑severity buffer overflow in a Tenda device, noting that a public exploit is available but without detailing the exploit code or confirming active attacks.

    0000065
    585 followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-3275 pertains to a critical security flaw found in the Tenda F453 router, specifically in the `fromAddressNat` function within the `/goform/addressNat` endpoint of the embedded HTTP daemon (`httpd`). The vulnerability arises from improper handling of user-supplied input in the `entrys` argument, leading to a buffer overflow condition. This flaw allows an attacker to execute arbitrary code remotely, without requiring authentication, potentially compromising the device entirely. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #BufferOverflow https://cvetodo.com/cve/CVE-2026-3275

    Post summary

    The text announces a critical buffer overflow in Tenda F453 routers, detailing the affected function and the potential for unauthenticated remote code execution.

    0000037
    20 followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting Tenda F453 (CVE-2026-3275) https://vuldb.com/?id.347999

    Post summary

    The note highlights that CVE-2026-3275 has an increased severity for the Tenda F453, but no further exploit, patch, or detailed technical info is provided.

    0000069
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf453---
OStendaf453_firmware1.0.0.3--

Explore more