CVE-2026-3272
Tenda F453 httpd DhcpListClient fromDhcpListClient buffer overflow
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.7EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
27 Feb 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. This manipulation of the argument page causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Affected products
Tenda · F453Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →