Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119)
A buffer overflow vulnerability in Tenda F453 version 1.0.0.3 exists in the fromSafeUrlFilter function of the /goform/SafeUrlFilter endpoint. The vulnerability is triggered through manipulation of the page parameter, allowing an attacker to overflow a memory buffer.
An authenticated attacker with low privileges can exploit this buffer overflow vulnerability remotely over the network without requiring user interaction. Successful exploitation could result in high impact to confidentiality, integrity, and availability of the affected system, potentially enabling arbitrary code execution, data theft, data modification, or service disruption. The exploit is publicly available and may be actively used.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
No patch information is available in the provided vulnerability data.
Prioritize immediate remediation of affected Tenda F453 1.0.0.3 devices. If a firmware update becomes available, apply it urgently given the HIGH severity rating and public exploit availability. Until patching is possible, implement network access controls to restrict access to the /goform/SafeUrlFilter endpoint, enforce strong authentication, and monitor for suspicious activity targeting this endpoint. Consider isolating affected devices from untrusted networks if patches are unavailable.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Feedly found the first article mentioning CVE-2026-3377 . See article
NVD published the first details for CVE-2026-3377
A CVSS base score of 8.8 has been assigned.
CVE-2026-3378: Buffer Overflow in Tenda F453 - Live Threat Intelligence - Threat Radar
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
