CVE-2026-3729Disclosure(tenda / f453)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in Tenda F453 1.0.0.3/3.As. Impacted is the function fromPptpUserAdd of the file /goform/PPTPDClient. Such manipulation of the argument username/opttype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f453
  • f453_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 5 mentions (2026-03-08); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
f453f453_firmware

2 versions affected across 2 products

Deep dive

Activity timeline9 mentions / 5d
01345Mentions · 2026-03-08: 5Mentions · 2026-03-09: 1Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-04-06: 1PoC Mentioned / Linked · 2026-03-08: 1Technical Details · 2026-03-08: 3Technical Details · 2026-03-09: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-04-06: 103-0803-0903-1203-1304-06
Signal classification3 categories
Disclosure
666.7%
General
222.2%
PoC
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-085
Disclosure3General1PoC1
2026-03-091
Disclosure1
2026-03-121
Disclosure1
2026-03-131
Disclosure1
2026-04-061
General1
Full discourse9 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3729 Tenda F453 Remote Stack Overflow Vulnerability in PPTPD Client Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3729

    Post summary

    The post identifies CVE-2026-3729 as a remote stack‑overflow vulnerability affecting the Tenda F453 PPTPD client, but offers no proof of concept, exploit, or patch details beyond a link to a vulnerability database entry.

    0001045
    4.0K followersView on X
  • David@DavidMarquet19
    General

    📌 Top CVEs recientes (CVSS>=7.0): 1. ⚠️ CVE-2026-3734 (CVSS: 7.3) 2. 🧱 CVE-2026-3732 (CVSS: 8.8) 3. 🧱 CVE-2026-3729 (CVSS: 8.8) 4. 🧱 CVE-2026-3728 (CVSS: 8.8) 5. 🧱 CVE-2026-3727 (CVSS: 8.8) #CyberSecurity #CVE #Infosec

    Post summary

    A short list of high‑CVSS CVEs (7.0+) is provided without further details on exploitation, patches, or proof‑of‑concepts.

    0000040
    163 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3729 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was identified in Tenda F453 1.0.0.3/3.As. Impacted is the function fromPptpUserAdd of the file /goform/..https://nvd.nist.gov/vuln/detail/CVE-2026-3729 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-3729 is a high‑severity vulnerability disclosed for Tenda F453 devices, affecting the fromPptpUserAdd function, but no PoC, exploit, or patch information is included.

    0000019
    172 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3729 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was identified in Tenda F453 1.0.0.3/3.As. Impacted is the function fromPptpUserAdd of the file /goform/..https://nvd.nist.gov/vuln/detail/CVE-2026-3729 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet reports on CVE‑2026‑3729, listing its CVSS score, affected Tenda device, and impacted function, but offers no PoC, exploit details, patches, or evidence of active exploitation.

    0000019
    172 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Tenda F453, Stack Buffer Overflow, #CVE-2026-3729 (High) https://dailycve.com/tenda-f453-stack-buffer-overflow-cve-2026-3729-high/

    Post summary

    A stack buffer overflow vulnerability (CVE‑2026‑3729) was disclosed for the Tenda F453 router, identified as high severity; the brief excerpt provides the type and severity but no PoC, exploit, patch, or active exploitation details.

    0000041
    166 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3729 A vulnerability was identified in Tenda F453 1.0.0.3/3.As. Impacted is the function fromPptpUserAdd of the file /goform/PPTPDClient. Such manipulation of the argument u… https://www.cve.org/CVERecord?id=CVE-2026-3729

    Post summary

    CVE‑2026‑3729 involves manipulation of the fromPptpUserAdd function in Tenda F453, but no PoC, exploit, patch, or active exploitation is reported.

    0000099
    56.6K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3729 - Tenda - F453 - https://www.redpacketsecurity.com/cve-alert-cve-2026-3729-tenda-f453/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3729 #tenda #f453

    Post summary

    The post announces a new CVE (CVE‑2026‑3729) affecting Tenda F453 but provides no technical or operational details beyond the alert link.

    0000098
    3.5K followersView on X
  • CVEFind.com@CveFindCom
    PoC

    [CVE-2026-3729: HIGH] Critical cyber security alert: Vulnerability found in Tenda F453 1.0.0.3/3.As allows remote execution of stack-based buffer overflow attack. Publicly available exploit poses serious threat.#cve,CVE-2026-3729,#cybersecurity https://cvefind.com/CVE-2026-3729

    Post summary

    CVE-2026‑3729, a high‑severity stack‑overflow RCE vulnerability in Tenda F453, is publicly reported with an available exploit, but no active exploitation, patch, or detailed code is mentioned.

    0000080
    600 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Tenda F453 (CVE-2026-3729) https://vuldb.com/?id.349707

    Post summary

    The post announces CVE-2026-3729, a newly disclosed vulnerability with increased severity for the Tenda F453, but provides no PoC, exploit code, active usage, patch, or detailed technical information.

    0000088
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf453---
OStendaf453_firmware1.0.0.3--

Explore more