CVE-2026-3377Disclosure(tenda / f453)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Performing a manipulation of the argument page results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f453
  • f453_firmware

Threat summary

  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 5 mentions (2026-03-01); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
f453f453_firmware

2 versions affected across 2 products

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-02-28: 1Mentions · 2026-03-01: 5Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 4Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 102-2803-0103-0503-06
Signal classification2 categories
Disclosure
562.5%
General
337.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-281
Disclosure1
2026-03-015
Disclosure4General1
2026-03-051
General1
2026-03-061
General1
Full discourse8 posts
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-3377 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file..https://nvd.nist.gov/vuln/detail/CVE-2026-3377 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-3377 is highlighted as a high‑severity vulnerability affecting the Tenda F453 router’s fromSafeUrlFilter function, but the post contains no proof of concept, exploit code, or patch details.

    0000023
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-3377 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file..https://nvd.nist.gov/vuln/detail/CVE-2026-3377 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2026‑3377 in a Tenda router, giving its CVSS score and impacted function, but offers no PoC, exploit, or patch details.

    0000027
    173 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3377 📊Severity: 8.8 🚨Risk Level: High 🧩Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3377 #CVE-2026-3377 #CVE #High #CyberSecurity #InfoSec https://t.co/UAfqsMKOpG

    Post summary

    The tweet announces CVE-2026-3377 with a severity of 8.8 and high risk, but offers no PoC, exploit, patch, or active exploitation details.

    0000051
    63 followersView on X
  • VulDB 🛡@vuldb
    General

    It is possible to see elevated activities targeting Tenda F453 (CVE-2026-3377) https://vuldb.com/?ctiid.348262

    Post summary

    The post notes increased activity against Tenda F453 linked to CVE-2026-3377 but provides no further details.

    0000078
    2.1K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3377 - Tenda F453 SafeUrlFilter fromSafeUrlFilter buffer overflow Intel Report: https://ift.tt/PZ2JNyl

    Post summary

    A new buffer overflow vulnerability (CVE-2026-3377) in Tenda F453's SafeUrlFilter has been reported, with an Intel report linked for further details.

    0000046
    343 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3377: HIGH] Critical security flaw identified in Tenda F453 1.0.0.3, affecting fromSafeUrlFilter function, allowing remote malicious attacks through buffer overflow. Take action immediately.#cve,CVE-2026-3377,#cybersecurity https://cvefind.com/CVE-2026-3377

    Post summary

    A high‑severity buffer overflow vulnerability in Tenda F453’s fromSafeUrlFilter function has been disclosed, but no PoC, exploit, or patch information is provided.

    0000057
    587 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3377 A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Performing a manipulatio… https://www.cve.org/CVERecord?id=CVE-2026-3377 ----- Traducción: CVE-2026-3377 Se … http://infoflow.cloud`

    Post summary

    A new vulnerability, CVE-2026-3377, has been identified in the Tenda F453 firmware, affecting the fromSafeUrlFilter function. Technical details are provided, and a link to the official CVE record is included.

    0000047
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3377 A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Performing a manipulatio… https://www.cve.org/CVERecord?id=CVE-2026-3377

    Post summary

    A vulnerability (CVE-2026-3377) was identified in Tenda F453 firmware, affecting the fromSafeUrlFilter function in /goform/SafeUrlFilter, but no PoC, exploit, or patch details are provided.

    00000662
    56.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf453---
OStendaf453_firmware1.0.0.3--

Explore more