Tenda M3 vulnerabilities

10 known vulnerabilities affecting tenda/m3.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH10

Vulnerabilities

Page 1 of 1
CVE-2026-5567HIGHCVSS 7.4v1.0.0.102026-04-05
CVE-2026-5567 [HIGH] CWE-119 CVE-2026-5567: A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Destination Handler. Executing a manipulation of the argument policyType can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.
cvelistv5nvd
CVE-2025-15253HIGHCVSS 7.4v1.0.0.13(4903)2025-12-30
CVE-2025-15253 [HIGH] CWE-119 CVE-2025-15253: A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown functi A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2025-15233HIGHCVSS 7.4v1.0.0.13(4903)2025-12-30
CVE-2025-15233 [HIGH] CWE-119 CVE-2025-15233: A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function form A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function formSetAdInfoDetails of the file /goform/setAdInfoDetail. The manipulation of the argument adName/smsPassword/smsAccount/weixinAccount/weixinName/smsSignature/adRedirectUrl/adCopyRight/smsContent/adItemUID results in heap-based buffer overflow. The attack m
cvelistv5nvd
CVE-2025-15252HIGHCVSS 7.4v1.0.0.13(4903)2025-12-30
CVE-2025-15252 [HIGH] CWE-119 CVE-2025-15252: A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemote A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the file /goform/setDhcpAP. This manipulation of the argument startip/endip/leasetime/gateway/dns1/dns2 causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.
cvelistv5nvd
CVE-2025-15231HIGHCVSS 7.4v1.0.0.13(4903)2025-12-30
CVE-2025-15231 [HIGH] CWE-119 CVE-2025-15231: A vulnerability was determined in Tenda M3 1.0.0.13(4903). This affects the function formSetRemoteVl A vulnerability was determined in Tenda M3 1.0.0.13(4903). This affects the function formSetRemoteVlanInfo of the file /goform/setVlanInfo. Executing a manipulation of the argument ID/vlan/port can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
cvelistv5nvd
CVE-2025-15230HIGHCVSS 7.4v1.0.0.13(4903)2025-12-30
CVE-2025-15230 [HIGH] CWE-119 CVE-2025-15230: A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSet A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSetVlanPolicy of the file /goform/setVlanPolicyData. Performing a manipulation of the argument qvlan_truck_port results in heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
cvelistv5nvd
CVE-2025-15232HIGHCVSS 7.4v1.0.0.13(4903)2025-12-30
CVE-2025-15232 [HIGH] CWE-119 CVE-2025-15232: A vulnerability was identified in Tenda M3 1.0.0.13(4903). This vulnerability affects the function f A vulnerability was identified in Tenda M3 1.0.0.13(4903). This vulnerability affects the function formSetAdPushInfo of the file /goform/setAdPushInfo. The manipulation of the argument mac/terminal leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
cvelistv5nvd
CVE-2025-15234HIGHCVSS 7.4v1.0.0.13(4903)2025-12-30
CVE-2025-15234 [HIGH] CWE-119 CVE-2025-15234: A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInt A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanInfo. This manipulation of the argument portIp/portMask/portGateWay/portDns/portSecDns causes heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available
cvelistv5nvd
CVE-2025-9299HIGHCVSS 7.4v1.0.0.122025-08-21
CVE-2025-9299 [HIGH] CWE-119 CVE-2025-9299: A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPassengerAnalyseData of the file /goform/getMasterPassengerAnalyseData. The manipulation of the argument Time leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be u
cvelistv5nvd
CVE-2025-9298HIGHCVSS 7.4v1.0.0.122025-08-21
CVE-2025-9298 [HIGH] CWE-119 CVE-2025-9298: A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /gof A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
cvelistv5nvd