Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.4

Tenda F453 Router Allows Remote Code Execution Through Malformed Input

CVE-2026-3729
Summary

A flaw in the Tenda F453 router's PPPoE client functionality allows an attacker to execute arbitrary code on the device by sending a specially crafted request. This could potentially give the attacker unauthorized access to the router and the network it manages. Users should update their Tenda F453 routers to the latest available version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
tenda f453_firmware 1.0.0.3 –
Original title
A vulnerability was identified in Tenda F453 1.0.0.3/3.As. Impacted is the function fromPptpUserAdd of the file /goform/PPTPDClient. Such manipulation of the argument username/opttype leads to stac...
Original description
A vulnerability was identified in Tenda F453 1.0.0.3/3.As. Impacted is the function fromPptpUserAdd of the file /goform/PPTPDClient. Such manipulation of the argument username/opttype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
nvd CVSS2.0 9.0
nvd CVSS3.1 8.8
nvd CVSS4.0 7.4
Vulnerability type
CWE-119 Buffer Overflow
CWE-121 Stack-based Buffer Overflow
Published: 8 Mar 2026 · Updated: 13 Mar 2026 · First seen: 8 Mar 2026