CVE-2026-3167 is a high-severity buffer overflow vulnerability affecting Tenda F453 1.0.0.3 firmware. Specifically, manipulating the 'webSiteId' argument within the 'formWebTypeLibrary' function of the '/goform/webtypelibrary' component can lead to remote code execution. With a CVSS score of 8.8, this vulnerability is easily exploitable over the network with low privileges and no user interaction, potentially resulting in complete compromise of confidentiality, integrity, and availability. While an exploit has been publicly released, there is no indication of active exploitation in the wild, nor are there Metasploit or Nuclei modules available. Community discussion is minimal, with only one mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.3CPE matchmatch criteria | cpe:2.3:o:tenda:f453_firmware:1.0.0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.