A security flaw has been discovered in Tenda F453 1.0.0.3. The impacted element is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component httpd. Performing a manipulation of the argument webSiteId results in buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-02-25
CVSS: 9.0
CVSS Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C
Download Exploit for CVE-2026-3167 here:
Use Tor Browser to access .onion site.
https://sonitex.com/exploit-149-cve-2025-40538/
https://sonitex.com/exploit-596-cve-2026-28438/