CVE-2026-3728Disclosure(tenda / f453)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Tenda F453 1.0.0.3/1.If. This issue affects the function fromSetCfm of the file /goform/setcfm. This manipulation of the argument funcname/funcpara1 causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f453
  • f453_firmware

Threat summary

  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-03-08); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
f453f453_firmware

2 versions affected across 2 products

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-03-08: 4Mentions · 2026-03-09: 1Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-04-06: 1Technical Details · 2026-03-08: 2Technical Details · 2026-03-09: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-04-06: 103-0803-0903-1203-1304-06
Signal classification2 categories
Disclosure
787.5%
General
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-084
Disclosure3General1
2026-03-091
Disclosure1
2026-03-121
Disclosure1
2026-03-131
Disclosure1
2026-04-061
Disclosure1
Full discourse8 posts
  • David@DavidMarquet19
    Disclosure

    📌 Top CVEs recientes (CVSS>=7.0): 1. ⚠️ CVE-2026-3734 (CVSS: 7.3) 2. 🧱 CVE-2026-3732 (CVSS: 8.8) 3. 🧱 CVE-2026-3729 (CVSS: 8.8) 4. 🧱 CVE-2026-3728 (CVSS: 8.8) 5. 🧱 CVE-2026-3727 (CVSS: 8.8) #CyberSecurity #CVE #Infosec

    Post summary

    The post lists several high‑CVSS CVEs (CVE-2026-3734 to 3727) but provides no deeper technical details, PoC links, exploit code, or mitigation information.

    0000040
    163 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3728 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was determined in Tenda F453 1.0.0.3/1.If. This issue affects the function fromSetCfm of the file /gofor..https://nvd.nist.gov/vuln/detail/CVE-2026-3728 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    This post announces a high‑severity vulnerability (CVE‑2026‑3728) in Tenda F453 firmware, including its CVSS score and affected function, but does not provide PoC, exploit code, or mitigation.

    0000028
    172 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3728 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was determined in Tenda F453 1.0.0.3/1.If. This issue affects the function fromSetCfm of the file /gofor..https://nvd.nist.gov/vuln/detail/CVE-2026-3728 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-3728 was identified in Tenda F453 firmware, with a CVSS score of 7.4, affecting the fromSetCfm function in the /gofor file.

    0000023
    172 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Tenda F453, Stack-based Buffer Overflow, #CVE-2026-3728 (Critical) https://dailycve.com/tenda-f453-stack-based-buffer-overflow-cve-2026-3728-critical/

    Post summary

    A new critical stack-based buffer overflow vulnerability (CVE-2026-3728) affecting the Tenda F453 router has been disclosed; no evidence of an exploit or mitigation is presented in the tweet.

    0000038
    166 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3728 A vulnerability was determined in Tenda F453 1.0.0.3/1.If. This issue affects the function fromSetCfm of the file /goform/setcfm. This manipulation of the argument func… https://www.cve.org/CVERecord?id=CVE-2026-3728

    Post summary

    The post announces a vulnerability (CVE‑2026‑3728) in Tenda F453, indicating that the /goform/setcfm function’s argument manipulation can be exploited, but it provides no evidence of active exploitation, PoC, patch, or false‑positive claim.

    00000103
    56.6K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3728 - Tenda - F453 - https://www.redpacketsecurity.com/cve-alert-cve-2026-3728-tenda-f453/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3728 #tenda #f453

    Post summary

    The post announces the CVE-2026-3728 vulnerability affecting Tenda F453 and directs readers to a security website for more information.

    0000089
    3.5K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3728: HIGH] Critical security flaw in Tenda F453 1.0.0.3/1.If allows remote attackers to conduct stack-based buffer overflow via manipulation of funcname/funcpara1 argument in /goform/setcfm, as deta...#cve,CVE-2026-3728,#cybersecurity https://cvefind.com/CVE-2026-3728

    Post summary

    The tweet announces a critical stack‑based buffer overflow (CVE‑2026‑3728) in Tenda F453 firmware, detailing the vulnerable parameters but offering no PoC, exploit code, or mitigation information.

    0000039
    600 followersView on X
  • VulDB 🛡@vuldb
    General

    There is a new vulnerability with elevated criticality in Tenda F453 (CVE-2026-3728) https://vuldb.com/?id.349706

    Post summary

    A new critical vulnerability, CVE-2026-3728, has been reported for the Tenda F453, but the post provides no additional technical details or mitigation information.

    00000115
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf453---
OStendaf453_firmware1.0.0.3--

Explore more