cbcvebase.

Tenda Ax3 Firmware vulnerabilities

53 known vulnerabilities affecting tenda/ax3_firmware.

Total CVEs
53
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL16HIGH36MEDIUM1

Vulnerabilities

Page 1 of 3
CVE-2023-27240P1CRITICALCVSS 9.8Exploitedv16.03.12.112023-03-15
CVE-2023-27240 [CRITICAL] CWE-77 CVE-2023-27240: Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip par Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip.
nvd
CVE-2022-24144P2CRITICALCVSS 9.8v16.03.12.10_cn2022-02-04
CVE-2022-24144 [CRITICAL] CWE-77 CVE-2022-24144: Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the functio Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function WanParameterSetting. This vulnerability allows attackers to execute arbitrary commands via the gateway, dns1, and dns2 parameters.
nvd
CVE-2021-46393P2CRITICALCVSS 9.8v16.03.12.102022-03-04
CVE-2021-46393 [CRITICAL] CWE-787 CVE-2021-46393: There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is directly retrieved from the http request parameter startIp. Then v10 will be splice to stack by function sscanf without any security check,which causes stack overflow. By POSTing the page /goform/SetPptpServerCf
nvd
CVE-2022-24150P2CRITICALCVSS 9.8v16.03.12.10_cn2022-02-04
CVE-2022-24150 [CRITICAL] CWE-77 CVE-2022-24150: Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the functio Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function formSetSafeWanWebMan. This vulnerability allows attackers to execute arbitrary commands via the remoteIp parameter.
nvd
CVE-2022-24148P2CRITICALCVSS 9.8v16.03.12.10_cn2022-02-04
CVE-2022-24148 [CRITICAL] CWE-77 CVE-2022-24148: Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the functio Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function mDMZSetCfg. This vulnerability allows attackers to execute arbitrary commands via the dmzIp parameter.
nvd
CVE-2025-69764P2CRITICALCVSS 9.8v16.03.12.112026-01-22
CVE-2025-69764 [CRITICAL] CWE-121 CVE-2025-69764: Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function d Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buffer, which may result in memory corruption and remote code execution.
nvd
CVE-2025-69763P2CRITICALCVSS 9.8v16.03.12.112026-01-21
CVE-2025-69763 [CRITICAL] CWE-121 CVE-2025-69763: Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, w Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remote code execution.
nvd
CVE-2025-69762P2CRITICALCVSS 9.8v16.03.12.112026-01-21
CVE-2025-69762 [CRITICAL] CWE-121 CVE-2025-69762: Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, whi Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory corruption and enable remote code execution.
nvd
CVE-2025-69766P2CRITICALCVSS 9.8v16.03.12.112026-01-21
CVE-2025-69766 [CRITICAL] CWE-121 CVE-2025-69766: Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function d Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution.
nvd
CVE-2021-46394P2CRITICALCVSS 9.8v16.03.12.102022-03-04
CVE-2021-46394 [CRITICAL] CWE-787 CVE-2021-46394: There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check, which causes stack overflow. By POSTing the page /goform/SetPptpServerC
nvd
CVE-2022-24995P3CRITICALCVSS 9.8v16.03.12.10_cn2022-03-10
CVE-2022-24995 [CRITICAL] CWE-787 CVE-2022-24995: Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.
nvd
CVE-2023-49409P3CRITICALCVSS 9.8v16.03.12.112023-12-07
CVE-2023-49409 [CRITICAL] CVE-2023-49409: Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet.
nvd
CVE-2023-27239P3CRITICALCVSS 9.8v16.03.12.112023-03-15
CVE-2023-27239 [CRITICAL] CWE-787 CVE-2023-27239: Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /g Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /goform/WifiGuestSet.
nvd
CVE-2023-51812P3CRITICALCVSS 9.8v16.03.12.112024-01-04
CVE-2023-51812 [CRITICAL] CWE-77 CVE-2023-51812: Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.
nvd
CVE-2023-49408P3CRITICALCVSS 9.8v16.03.12.112023-12-07
CVE-2023-49408 [CRITICAL] CWE-787 CVE-2023-49408: Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name. Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name.
nvd
CVE-2023-24212P3CRITICALCVSS 9.8v16.03.12.112023-02-23
CVE-2023-24212 [CRITICAL] CWE-787 CVE-2023-24212: Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /gofo Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.
nvd
CVE-2025-69765P3HIGHCVSS 7.5v16.03.12.112026-03-03
CVE-2025-69765 [HIGH] CWE-121 CVE-2025-69765: Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list param Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can cause memory corruption and enable remote code execution.
nvd
CVE-2023-47422P3HIGHCVSS 8.8v16.03.12.112024-02-20
CVE-2023-47422 [HIGH] CWE-284 CVE-2023-47422: An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
nvd
CVE-2023-27042P3HIGHCVSS 8.8v16.03.12.112023-03-24
CVE-2023-27042 [HIGH] CWE-787 CVE-2023-27042: Tenda AX3 V16.03.12.11 is vulnerable to Buffer Overflow via /goform/SetFirewallCfg. Tenda AX3 V16.03.12.11 is vulnerable to Buffer Overflow via /goform/SetFirewallCfg.
nvd
CVE-2025-55605P3HIGHCVSS 7.5v16.03.12.10_cn2025-08-22
CVE-2025-55605 [HIGH] CWE-120 CVE-2025-55605: Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the saveParentControlInfo function via Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the saveParentControlInfo function via the deviceName parameter.
nvd
Tenda Ax3 Firmware vulnerabilities | cvebase