Critical Buffer Overflow Vulnerabilities in Tenda Devices Identified
Article Content
Two significant buffer overflow vulnerabilities have been discovered in Tenda devices. CVE-2026-4553 affects Tenda F453 firmware version 1.0.0.3, allowing authenticated attackers to exploit a stack-based buffer overflow via the /goform/Natlimit component. This vulnerability has a CVSS score of 8.8 and could lead to complete system compromise. CVE-2026-4565 impacts Tenda AC21 version 16.03.08.16, where improper handling of arguments in the /goform/SetNetControlList file can also be exploited by low-privilege authenticated users. This vulnerability similarly has a CVSS score of 8.8 and can result in unauthorized access and denial of service. Both vulnerabilities require network access and low-level authentication but do not necessitate user interaction. Currently, no patches are available for either vulnerability, and monitoring for suspicious activity is advised.
Key Points: • CVE-2026-4553 and CVE-2026-4565 are critical vulnerabilities in Tenda devices. • Both vulnerabilities allow low-privilege authenticated attackers to exploit remotely. • No patches are currently available; immediate action is recommended to mitigate risks.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.