


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the component httpd. This mani…
Published:
28 maart 2026 om 23:00:00
Alert date:
29 maart 2026 om 03:00:32
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A critical vulnerability has been discovered in Tenda F453 router firmware version 1.0.0.3. The flaw affects the fromPPTPUserSetting function in the /goform/PPTPUserSetting file within the httpd component. An attacker can manipulate the 'delno' argument to trigger a stack-based buffer overflow. The vulnerability allows for remote exploitation without authentication. Public exploits are already available, making this a high-priority security issue. Organizations using affected Tenda F453 routers should apply patches immediately or implement mitigating controls.
Technical details
Mitigation steps:
Affected products:
Tenda F453
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-5021
https://github.com/Litengzheng/vul_db/blob/main/F453/vul_92/README.md
https://vuldb.com/submit/778415
https://vuldb.com/vuln/353906
https://vuldb.com/vuln/353906/cti
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
