CVE-2026-3398Disclosure(tenda / f453)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a manipulation of the argument wanmode/PPPOEPassword can lead to buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f453
  • f453_firmware

Threat summary

  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-03-01); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
f453f453_firmware

2 versions affected across 2 products

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-03-01: 4Mentions · 2026-03-02: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Technical Details · 2026-03-01: 3Technical Details · 2026-03-02: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 103-0103-0203-0503-06
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-014
Disclosure3General1
2026-03-021
Disclosure1
2026-03-051
Disclosure1
2026-03-061
Disclosure1
Full discourse7 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3398 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetW..https://nvd.nist.gov/vuln/detail/CVE-2026-3398 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces the analysis of CVE-2026-3398, providing CVSS, device details, and the affected function, but offers no PoC, exploit, or patch information.

    0000026
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3398 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetW..https://nvd.nist.gov/vuln/detail/CVE-2026-3398 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces the discovery of CVE‑2026‑3398 on Tenda F453 devices, providing CVSS score and affected function but no PoC or fix info.

    0000024
    173 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3398 - Tenda F453 httpd AdvSetWan fromAdvSetWan buffer overflow Intel Report: https://ift.tt/r9hqP2X

    Post summary

    A new buffer overflow vulnerability (CVE-2026-3398) in Tenda F453 httpd's AdvSetWan function has been reported, with an Intel report linked for further details.

    0000046
    342 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-3398 A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a manipulat… https://www.cve.org/CVERecord?id=CVE-2026-3398 ----- Traducción: CVE-2026-3398 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑3398 affecting Tenda F453, noting the affected function and file, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000041
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3398 A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a manipulat… https://www.cve.org/CVERecord?id=CVE-2026-3398

    Post summary

    A vulnerability in Tenda F453’s httpd component’s fromAdvSetWan function was identified, but no PoC, exploit, or patch details are provided.

    00000462
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3398: HIGH] Vulnerability found in Tenda F453 1.0.0.3: Remote attackers can execute a buffer overflow attack by manipulating the argument wanmode/PPPOEPassword in the httpd component.#cve,CVE-2026-3398,#cybersecurity https://cvefind.com/CVE-2026-3398

    Post summary

    A buffer overflow vulnerability (CVE-2026-3398) was disclosed in Tenda F453 firmware, allowing remote attackers to execute code by manipulating the wanmode/PPPOEPassword parameter in the httpd component.

    0000068
    587 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3398 Tenda F453 Remote Buffer Overflow Vulnerability in PPPOE Configuration Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3398

    Post summary

    A new remote buffer overflow vulnerability (CVE-2026-3398) has been disclosed for the Tenda F453 PPPOE configuration handler, but no PoC, exploit, or patch details are provided.

    0000065
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf453---
OStendaf453_firmware1.0.0.3--

Explore more