Tenda M3 Firmware vulnerabilities
44 known vulnerabilities affecting tenda/m3_firmware.
Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH27
Vulnerabilities
Page 1 of 3
CVE-2025-15253HIGHCVSS 7.4v1.0.0.13\(4903\)2025-12-30
CVE-2025-15253 [HIGH] CWE-119 CVE-2025-15253: A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown functi
A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-15233HIGHCVSS 7.4v1.0.0.13\(4903\)2025-12-30
CVE-2025-15233 [HIGH] CWE-119 CVE-2025-15233: A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function form
A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function formSetAdInfoDetails of the file /goform/setAdInfoDetail. The manipulation of the argument adName/smsPassword/smsAccount/weixinAccount/weixinName/smsSignature/adRedirectUrl/adCopyRight/smsContent/adItemUID results in heap-based buffer overflow. The attack m
nvd
CVE-2025-15252HIGHCVSS 7.4v1.0.0.13\(4903\)2025-12-30
CVE-2025-15252 [HIGH] CWE-119 CVE-2025-15252: A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemote
A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the file /goform/setDhcpAP. This manipulation of the argument startip/endip/leasetime/gateway/dns1/dns2 causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.
nvd
CVE-2025-15230HIGHCVSS 7.4v1.0.0.13\(4903\)2025-12-30
CVE-2025-15230 [HIGH] CWE-119 CVE-2025-15230: A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSet
A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSetVlanPolicy of the file /goform/setVlanPolicyData. Performing a manipulation of the argument qvlan_truck_port results in heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
nvd
CVE-2025-15232HIGHCVSS 7.4v1.0.0.13\(4903\)2025-12-30
CVE-2025-15232 [HIGH] CWE-119 CVE-2025-15232: A vulnerability was identified in Tenda M3 1.0.0.13(4903). This vulnerability affects the function f
A vulnerability was identified in Tenda M3 1.0.0.13(4903). This vulnerability affects the function formSetAdPushInfo of the file /goform/setAdPushInfo. The manipulation of the argument mac/terminal leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
nvd
CVE-2025-15231HIGHCVSS 7.4v1.0.0.13\(4903\)2025-12-30
CVE-2025-15231 [HIGH] CWE-119 CVE-2025-15231: A vulnerability was determined in Tenda M3 1.0.0.13(4903). This affects the function formSetRemoteVl
A vulnerability was determined in Tenda M3 1.0.0.13(4903). This affects the function formSetRemoteVlanInfo of the file /goform/setVlanInfo. Executing a manipulation of the argument ID/vlan/port can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2025-15234HIGHCVSS 7.4v1.0.0.13\(4903\)2025-12-30
CVE-2025-15234 [HIGH] CWE-119 CVE-2025-15234: A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInt
A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanInfo. This manipulation of the argument portIp/portMask/portGateWay/portDns/portSecDns causes heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available
nvd
CVE-2025-9299HIGHCVSS 7.4v1.0.0.122025-08-21
CVE-2025-9299 [HIGH] CWE-119 CVE-2025-9299: A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function
A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPassengerAnalyseData of the file /goform/getMasterPassengerAnalyseData. The manipulation of the argument Time leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be u
nvd
CVE-2025-9298HIGHCVSS 7.4v1.0.0.122025-08-21
CVE-2025-9298 [HIGH] CWE-119 CVE-2025-9298: A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /gof
A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
nvd
CVE-2023-51095CRITICALCVSS 9.8v1.0.0.12\(4856\)2023-12-26
CVE-2023-51095 [CRITICAL] CWE-787 CVE-2023-51095: Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPoli
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.
nvd
CVE-2023-51091CRITICALCVSS 9.8v1.0.0.12\(4856\)2023-12-26
CVE-2023-51091 [CRITICAL] CWE-787 CVE-2023-51091: Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityH
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler.
nvd
CVE-2023-51093CRITICALCVSS 9.8v1.0.0.12\(4856\)2023-12-26
CVE-2023-51093 [CRITICAL] CWE-787 CVE-2023-51093: Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVla
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo.
nvd
CVE-2023-51090CRITICALCVSS 9.8v1.0.0.12\(4856\)2023-12-26
CVE-2023-51090 [CRITICAL] CWE-787 CVE-2023-51090: Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinCo
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig.
nvd
CVE-2023-51094CRITICALCVSS 9.8v1.0.0.12\(4856\)2023-12-26
CVE-2023-51094 [CRITICAL] CWE-78 CVE-2023-51094: Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the functio
Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet.
nvd
CVE-2023-51092CRITICALCVSS 9.8v1.0.0.12\(4856\)2023-12-26
CVE-2023-51092 [CRITICAL] CWE-787 CVE-2023-51092: Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.
nvd
CVE-2022-38570HIGHCVSS 7.5v1.0.0.12\(4856\)2022-08-28
CVE-2022-38570 [HIGH] CWE-787 CVE-2022-38570: Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd.
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adPushUID parameter.
nvd
CVE-2022-38564HIGHCVSS 7.5v1.0.0.12\(4856\)2022-08-28
CVE-2022-38564 [HIGH] CWE-787 CVE-2022-38564: Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function f
Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function formSetPicListItem. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adItemUID parameter.
nvd
CVE-2022-38562HIGHCVSS 7.5v1.0.0.12\(4856\)2022-08-28
CVE-2022-38562 [HIGH] CWE-787 CVE-2022-38562: Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the funct
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the lan parameter.
nvd
CVE-2022-38569HIGHCVSS 7.5v1.0.0.12\(4856\)2022-08-28
CVE-2022-38569 [HIGH] CWE-787 CVE-2022-38569: Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelAd.
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelAd.
nvd
CVE-2022-38568HIGHCVSS 7.5v1.0.0.12\(4856\)2022-08-28
CVE-2022-38568 [HIGH] CWE-787 CVE-2022-38568: Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the funct
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the hostname parameter.
nvd
1 / 3Next →