Tenda Ax3 Firmware vulnerabilities
53 known vulnerabilities affecting tenda/ax3_firmware.
Total CVEs
53
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL16HIGH36MEDIUM1
Vulnerabilities
Page 2 of 3
CVE-2025-55603P3HIGHCVSS 7.5v16.03.12.10_cn2025-08-22
CVE-2025-55603 [HIGH] CWE-120 CVE-2025-55603: Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromSetSysTime function via the nt
Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromSetSysTime function via the ntpServer parameter.
nvd
CVE-2025-55606P3HIGHCVSS 7.5v16.03.12.10_cn2025-08-22
CVE-2025-55606 [HIGH] CWE-120 CVE-2025-55606: Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromAdvSetMacMtuWan function via t
Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromAdvSetMacMtuWan function via the serverName parameter.
nvd
CVE-2025-71026P3HIGHCVSS 7.5v16.03.12.10_cn2026-01-13
CVE-2025-71026 [HIGH] CWE-787 CVE-2025-71026: Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanSpeed2 parameter of
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanSpeed2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-71023P3HIGHCVSS 7.5v16.03.12.10_cn2026-01-13
CVE-2025-71023 [HIGH] CWE-121 CVE-2025-71023: Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the mac2 parameter of the f
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the mac2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-71027P3HIGHCVSS 7.5v16.03.12.10_cn2026-01-13
CVE-2025-71027 [HIGH] CWE-787 CVE-2025-71027: Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanMTU2 parameter of th
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanMTU2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-71025P3HIGHCVSS 7.5v16.03.12.10_cn2026-01-13
CVE-2025-71025 [HIGH] CWE-787 CVE-2025-71025: Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the cloneType2 parameter of
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the cloneType2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-71024P3HIGHCVSS 7.5v16.03.12.10_cn2026-01-13
CVE-2025-71024 [HIGH] CWE-787 CVE-2025-71024: Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the serviceName2 parameter
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the serviceName2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63455P3HIGHCVSS 7.5v16.03.12.102025-11-10
CVE-2025-63455 [HIGH] CWE-121 CVE-2025-63455: Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the shareSpeed parameter i
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63454P3HIGHCVSS 7.5v16.03.12.10_cn2025-10-31
CVE-2025-63454 [HIGH] CWE-121 CVE-2025-63454: Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63149P3HIGHCVSS 7.5v16.03.12.102025-11-10
CVE-2025-63149 [HIGH] CWE-121 CVE-2025-63149: Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the ge
Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63147P3HIGHCVSS 7.5v16.03.12.102025-11-10
CVE-2025-63147 [HIGH] CWE-787 CVE-2025-63147: Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the deviceId parameter of th
Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the deviceId parameter of the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-63152P3HIGHCVSS 7.5v16.03.12.102025-11-10
CVE-2025-63152 [HIGH] CWE-121 CVE-2025-63152: Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter
Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter of the wlSetExternParameter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2022-24143P3HIGHCVSS 7.5v16.03.12.10_cn2022-02-04
CVE-2022-24143 [HIGH] CWE-787 CVE-2022-24143: Tenda AX3 v16.03.12.10_CN and AX12 22.03.01.2_CN was discovered to contain a stack overflow in the f
Tenda AX3 v16.03.12.10_CN and AX12 22.03.01.2_CN was discovered to contain a stack overflow in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.
nvd
CVE-2022-24156P3HIGHCVSS 7.5v16.03.12.10_cn2022-02-04
CVE-2022-24156 [HIGH] CWE-787 CVE-2022-24156: Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetVirtualS
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetVirtualSer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.
nvd
CVE-2022-24160P3HIGHCVSS 7.5v16.03.12.10_cn2022-02-04
CVE-2022-24160 [HIGH] CWE-787 CVE-2022-24160: Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetDeviceNa
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetDeviceName. This vulnerability allows attackers to cause a Denial of Service (DoS) via the devName parameter.
nvd
CVE-2022-24152P3HIGHCVSS 7.5v16.03.12.10_cn2022-02-04
CVE-2022-24152 [HIGH] CWE-787 CVE-2022-24152: Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetRouteSta
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetRouteStatic. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.
nvd
CVE-2022-24163P3HIGHCVSS 7.5v16.03.12.10_cn2022-02-04
CVE-2022-24163 [HIGH] CWE-787 CVE-2022-24163: Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime.
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.
nvd
CVE-2022-24146P3HIGHCVSS 7.5v16.03.12.10_cn2022-02-04
CVE-2022-24146 [HIGH] CWE-787 CVE-2022-24146: Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetQosBand.
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetQosBand. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.
nvd
CVE-2022-24153P3HIGHCVSS 7.5v16.03.12.10_cn2022-02-04
CVE-2022-24153 [HIGH] CWE-787 CVE-2022-24153: Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formAddMacfilte
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formAddMacfilterRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the devName parameter.
nvd
CVE-2022-24151P3HIGHCVSS 7.5v16.03.12.10_cn2022-02-04
CVE-2022-24151 [HIGH] CWE-787 CVE-2022-24151: Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetWifiGuse
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetWifiGusetBasic. This vulnerability allows attackers to cause a Denial of Service (DoS) via the shareSpeed parameter.
nvd