CVE-2026-6989General(tenda / f453)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch tenda f453 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f453
  • f453_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-25); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
f453f453_firmware

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-25: 1Mentions · 2026-04-26: 1Active Exploitation · 2026-04-26: 1Patch / Workaround · 2026-04-26: 1Technical Details · 2026-04-26: 104-2504-26
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-251
General1
2026-04-261
Active Exploitation1
Full discourse2 posts
  • NerdieNews@NewsNerdie
    Active Exploitation

    Tenda F453 CVE-2026-6989 is under active exploitation—attackers can inject commands via Telnet, gaining full control. With a CVSS score of 9.8, patch now or risk widespread compromise. #NerdieNews #CyberSecurity #InfoSec #ThreatIntel #APT #Microsoft https://t.co/Yb9cIlwQfk

    Post summary

    The post indicates that CVE-2026-6989 is actively exploited via Telnet command injection with a high CVSS score, urging immediate patching.

    0000040
    57 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6989 A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipu… https://www.cve.org/CVERecord?id=CVE-2026-6989

    Post summary

    A CVE‑2026‑6989 vulnerability was reported in the Tenda F453 router’s Telnet service, with minimal technical details provided. No proof‑of‑concept, exploit code, patch, or active exploitation evidence is mentioned.

    0000038
    57.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaf453---
OStendaf453_firmware1.0.0.3--

Explore more