Tenda M3 Firmware vulnerabilities
45 known vulnerabilities affecting tenda/m3_firmware.
Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH26
Vulnerabilities
Page 1 of 3
CVE-2025-15252P2HIGHCVSS 8.8v1.0.0.13\(4903\)2025-12-30
CVE-2025-15252 [HIGH] CWE-119 CVE-2025-15252: A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemote
A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the file /goform/setDhcpAP. This manipulation of the argument startip/endip/leasetime/gateway/dns1/dns2 causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.
nvd
CVE-2025-9299P2CRITICALCVSS 9.8v1.0.0.122025-08-21
CVE-2025-9299 [CRITICAL] CWE-119 CVE-2025-9299: A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function
A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPassengerAnalyseData of the file /goform/getMasterPassengerAnalyseData. The manipulation of the argument Time leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may
nvd
CVE-2023-51092P2CRITICALCVSS 9.8v1.0.0.12\(4856\)2023-12-26
CVE-2023-51092 [CRITICAL] CWE-787 CVE-2023-51092: Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.
nvd
CVE-2025-15231P2HIGHCVSS 8.8v1.0.0.13\(4903\)2025-12-30
CVE-2025-15231 [HIGH] CWE-119 CVE-2025-15231: A vulnerability was determined in Tenda M3 1.0.0.13(4903). This affects the function formSetRemoteVl
A vulnerability was determined in Tenda M3 1.0.0.13(4903). This affects the function formSetRemoteVlanInfo of the file /goform/setVlanInfo. Executing a manipulation of the argument ID/vlan/port can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2025-15253P2HIGHCVSS 8.8v1.0.0.13\(4903\)2025-12-30
CVE-2025-15253 [HIGH] CWE-119 CVE-2025-15253: A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown functi
A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2023-51091P2CRITICALCVSS 9.8v1.0.0.12\(4856\)2023-12-26
CVE-2023-51091 [CRITICAL] CWE-787 CVE-2023-51091: Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityH
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler.
nvd
CVE-2025-9298P2CRITICALCVSS 9.8v1.0.0.122025-08-21
CVE-2025-9298 [CRITICAL] CWE-119 CVE-2025-9298: A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /gof
A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
nvd
CVE-2025-15234P2HIGHCVSS 8.8v1.0.0.13\(4903\)2025-12-30
CVE-2025-15234 [HIGH] CWE-119 CVE-2025-15234: A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInt
A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanInfo. This manipulation of the argument portIp/portMask/portGateWay/portDns/portSecDns causes heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available
nvd
CVE-2025-15232P2HIGHCVSS 8.8v1.0.0.13\(4903\)2025-12-30
CVE-2025-15232 [HIGH] CWE-119 CVE-2025-15232: A vulnerability was identified in Tenda M3 1.0.0.13(4903). This vulnerability affects the function f
A vulnerability was identified in Tenda M3 1.0.0.13(4903). This vulnerability affects the function formSetAdPushInfo of the file /goform/setAdPushInfo. The manipulation of the argument mac/terminal leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
nvd
CVE-2026-5567P2HIGHCVSS 8.8v1.0.0.102026-04-05
CVE-2026-5567 [HIGH] CWE-119 CVE-2026-5567: A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData
A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Destination Handler. Executing a manipulation of the argument policyType can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.
nvd
CVE-2025-15233P2HIGHCVSS 8.8v1.0.0.13\(4903\)2025-12-30
CVE-2025-15233 [HIGH] CWE-119 CVE-2025-15233: A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function form
A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function formSetAdInfoDetails of the file /goform/setAdInfoDetail. The manipulation of the argument adName/smsPassword/smsAccount/weixinAccount/weixinName/smsSignature/adRedirectUrl/adCopyRight/smsContent/adItemUID results in heap-based buffer overflow. The attack m
nvd
CVE-2025-15230P2HIGHCVSS 8.8v1.0.0.13\(4903\)2025-12-30
CVE-2025-15230 [HIGH] CWE-119 CVE-2025-15230: A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSet
A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSetVlanPolicy of the file /goform/setVlanPolicyData. Performing a manipulation of the argument qvlan_truck_port results in heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
nvd
CVE-2022-27083P2CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-27083 [CRITICAL] CWE-77 CVE-2022-27083: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic.
nvd
CVE-2022-27082P2CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-27082 [CRITICAL] CWE-77 CVE-2022-27082: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo.
nvd
CVE-2022-26290P2CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-26290 [CRITICAL] CWE-78 CVE-2022-26290: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac.
nvd
CVE-2022-27079P2CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-27079 [CRITICAL] CWE-77 CVE-2022-27079: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem.
nvd
CVE-2022-27077P2CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-27077 [CRITICAL] CWE-77 CVE-2022-27077: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic.
nvd
CVE-2022-27078P2CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-27078 [CRITICAL] CWE-77 CVE-2022-27078: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setAdInfoDetail.
nvd
CVE-2022-26289P2CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-26289 [CRITICAL] CWE-78 CVE-2022-26289: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeCommand.
nvd
CVE-2022-27080P2CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-27080 [CRITICAL] CWE-77 CVE-2022-27080: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode.
nvd
1 / 3Next →