CVE-2026-3380 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: March 3, 2026
Tenda F453 - Buffer Overflow
Overview
Tenda F453 1.0.0.3 contains a buffer overflow caused by manipulation of the "page" argument in /goform/L7Im, letting remote attackers cause memory corruption, exploit requires no special privileges.
Severity & Score
Impact
Remote attackers can cause memory corruption, potentially leading to denial of service or remote code execution.
Mitigation
Update to the latest version.
References
Social Media Activity(2 posts)
šØ CVE-2026-3380: HIGH-severity buffer overflow in Tenda F453 (v1.0.0.3). Remotely exploitable, no auth needed ā PoC public. Isolate devices, restrict WAN, monitor for /goform/L7Im traffic. Patch pending. https://radar.offseq.com/threat/cve-2026-3380-buffer-overflow-in-tenda-f453-54481f34 #OffSeq #Vulnerability #Tenda #InfoSec
View original postš CVE-2026-3380 - High (8.8) A vulnerability was found in Tenda F453 1.0.0.3. This issue affects the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argument page results in buffer overflow. The attack may be launched remotely. The exploit has been made... š https://www.thehackerwire.com/vulnerability/CVE-2026-3380/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-3380
- Severity
- High
- CVSS Score
- 8.8
- Type
- buffer_overflow
- Status
- confirmed
- EPSS
- 4.6%
- Social Posts
- 2
CWE
- CWE-119
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H