CVE-2025-1895Improper Restriction of Operations within the Bounds of a Memory Buffer in TX3

Severity
7.1HIGHNVD
EPSS
0.1%
top 78.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 4

Description

A vulnerability classified as critical has been found in Tenda TX3 16.03.13.11_multi. This affects an unknown part of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5tenda/tx316.03.13.11_multi
NVDtenda/tx3_firmware16.03.13.11

🔴Vulnerability Details

2
GHSA
GHSA-vh4r-x4qv-hfq7: A vulnerability classified as critical has been found in Tenda TX3 162025-03-04
CVEList
Tenda TX3 setMacFilterCfg buffer overflow2025-03-04
CVE-2025-1895 — Tenda TX3 vulnerability | cvebase