CVE-2026-3378Disclosure(tenda / f453)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Executing a manipulation of the argument qos can lead to buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f453
  • f453_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • Exploit: 1 classified signal
  • Peaked 2d ago at 6 mentions (2026-03-01); latest day: 1
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
f453f453_firmware

2 versions affected across 2 products

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-03-01: 6Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-01: 1Technical Details · 2026-03-01: 6Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 103-0103-0503-06
Signal classification2 categories
Disclosure
787.5%
Exploit
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-016
Disclosure5Exploit1
2026-03-051
Disclosure1
2026-03-061
Disclosure1
Full discourse8 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3378 (CVSS:7.4, HIGH) is Analyzed. A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Ex..https://nvd.nist.gov/vuln/detail/CVE-2026-3378 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces the discovery of CVE‑2026‑3378 in Tenda F453 routers, providing CVSS details and the affected function, but offers no PoC, exploit, patch, or active exploitation information.

    0000021
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3378 (CVSS:7.4, HIGH) is Analyzed. A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Ex..https://nvd.nist.gov/vuln/detail/CVE-2026-3378 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces the discovery and severity of CVE-2026-3378 affecting Tenda F453 firmware, but it lacks evidence of active exploitation, a PoC, or an available fix.

    0000022
    173 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3378 📊Severity: 8.8 🚨Risk Level: High 🧩Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3378 #CVE-2026-3378 #CVE #High #CyberSecurity #InfoSec https://t.co/peGXbUiAQ1

    Post summary

    A new high‑severity CVE (CVE‑2026‑3378) has been announced with a CVSS score of 8.8, affecting multiple unspecified products, but no further details or mitigation information are provided.

    0000050
    63 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3378 A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Executing a manipulation of the argument qos can l… https://www.cve.org/CVERecord?id=CVE-2026-3378 ----- Traducción: Se ha encontrado … http://infoflow.cloud`

    Post summary

    A new vulnerability, CVE-2026-3378, has been disclosed affecting Tenda F453 routers, detailing the impacted function and argument manipulation.

    0000096
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3378 A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Executing a manipulation of the argument qos can l… https://www.cve.org/CVERecord?id=CVE-2026-3378

    Post summary

    A vulnerability was identified in the Tenda F453 firmware affecting the qossetting function, but no exploit, patch, or active exploitation details are provided.

    00000823
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3378 - Tenda F453 qossetting fromqossetting buffer overflow Intel Report: https://ift.tt/8JIM7es

    Post summary

    A new buffer overflow vulnerability (CVE-2026-3378) in Tenda F453's qossetting has been reported, with an Intel report linked, but no PoC, exploit, or patch details are provided.

    0000050
    343 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3378 Tenda F453 Remote Buffer Overflow Vulnerability in QoS Settings Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3378

    Post summary

    A remote buffer overflow vulnerability (CVE-2026-3378) has been disclosed for the Tenda F453 router’s QoS settings function, with no PoC, exploit, or patch details provided.

    00000105
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-3378: HIGH] Critical remote code execution vulnerability discovered in Tenda F453 1.0.0.3. Act on the fromqossetting function to trigger buffer overflow. Exploit available for remote attacks.#cve,CVE-2026-3378,#cybersecurity https://cvefind.com/CVE-2026-3378

    Post summary

    A critical RCE vulnerability (CVE-2026-3378) in the Tenda F453 router allows remote attackers to trigger a buffer overflow via the fromqossetting function, with an exploit already available.

    0000065
    587 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf453---
OStendaf453_firmware1.0.0.3--

Explore more