Two high-severity vulnerabilities have been disclosed in Tenda router firmware, affecting FH451 1.0.0.9 and F453 1.0.0.3. The flaws are tracked as CVE-2026-4534 and CVE-2026-4552 and both involve remotely reachable stack-based buffer overflows in web management handlers. In the FH451 case, the issue is in the formWrlExtraSet function exposed through the /goform/WrlExtraSet component, where manipulation of the GO argument can trigger memory corruption. In the F453 case, the vulnerable code is the fromVirtualSer function behind the /goform/VirtualSer endpoint, where the page argument can be abused to cause a similar overflow.
Both CVE records indicate that public exploits are available, increasing the likelihood of opportunistic attacks against exposed devices. The disclosures map the weaknesses to CWE-119 and CWE-121, reflecting out-of-bounds memory handling and stack-based buffer overflow conditions, and the published scoring points to high impact on confidentiality, integrity, and availability. Organizations using these Tenda models should treat the flaws as urgent remote compromise risks, especially where router administration interfaces are internet-accessible.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A CVE entry was published for a remotely exploitable stack-based buffer overflow in Tenda F453 firmware version 1.0.0.3. The issue affects the fromVirtualSer function in the /goform/VirtualSer endpoint via the page argument, and the disclosure states that a public exploit is available.
A CVE entry was published for a remotely exploitable stack-based buffer overflow in Tenda FH451 version 1.0.0.9. The flaw affects the formWrlExtraSet function in /goform/WrlExtraSet via manipulation of the GO argument, and the disclosure notes a public exploit is available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.