Tenda Tx3 Firmware vulnerabilities

14 known vulnerabilities affecting tenda/tx3_firmware.

Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH7

Vulnerabilities

Page 1 of 1
CVE-2026-2137HIGHCVSS 7.4≤ 16.03.13.112026-02-08
CVE-2026-2137 [HIGH] CWE-119 CVE-2026-2137: A vulnerability has been found in Tenda TX3 up to 16.03.13.11_multi. This impacts an unknown functio A vulnerability has been found in Tenda TX3 up to 16.03.13.11_multi. This impacts an unknown function of the file /goform/SetIpMacBind. The manipulation of the argument list leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-8958HIGHCVSS 7.4v16.03.13.11_multi_tde012025-08-14
CVE-2025-8958 [HIGH] CWE-119 CVE-2025-8958: A vulnerability was identified in Tenda TX3 16.03.13.11_multi_TDE01. Affected by this vulnerability A vulnerability was identified in Tenda TX3 16.03.13.11_multi_TDE01. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-1896HIGHCVSS 7.1v16.03.13.112025-03-04
CVE-2025-1896 [HIGH] CWE-119 CVE-2025-1896: A vulnerability classified as critical was found in Tenda TX3 16.03.13.11_multi. This vulnerability A vulnerability classified as critical was found in Tenda TX3 16.03.13.11_multi. This vulnerability affects unknown code of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-1897HIGHCVSS 7.1v16.03.13.112025-03-04
CVE-2025-1897 [HIGH] CWE-119 CVE-2025-1897: A vulnerability, which was classified as critical, has been found in Tenda TX3 16.03.13.11_multi. Th A vulnerability, which was classified as critical, has been found in Tenda TX3 16.03.13.11_multi. This issue affects some unknown processing of the file /goform/SetNetControlList. The manipulation of the argument list leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-1899HIGHCVSS 7.1v16.03.13.112025-03-04
CVE-2025-1899 [HIGH] CWE-119 CVE-2025-1899: A vulnerability has been found in Tenda TX3 16.03.13.11_multi and classified as critical. Affected b A vulnerability has been found in Tenda TX3 16.03.13.11_multi and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-1898HIGHCVSS 7.1v16.03.13.112025-03-04
CVE-2025-1898 [HIGH] CWE-119 CVE-2025-1898: A vulnerability, which was classified as critical, was found in Tenda TX3 16.03.13.11_multi. Affecte A vulnerability, which was classified as critical, was found in Tenda TX3 16.03.13.11_multi. Affected is an unknown function of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime/schedEndTime leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-1895HIGHCVSS 7.1v16.03.13.112025-03-04
CVE-2025-1895 [HIGH] CWE-119 CVE-2025-1895: A vulnerability classified as critical has been found in Tenda TX3 16.03.13.11_multi. This affects a A vulnerability classified as critical has been found in Tenda TX3 16.03.13.11_multi. This affects an unknown part of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2022-43028CRITICALCVSS 9.8v16.03.13.112022-10-19
CVE-2022-43028 [CRITICAL] CWE-787 CVE-2022-43028: Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the t Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter at /goform/SetSysTimeCfg.
nvd
CVE-2022-43025CRITICALCVSS 9.8v16.03.13.112022-10-19
CVE-2022-43025 [CRITICAL] CWE-787 CVE-2022-43025: Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the s Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the startIp parameter at /goform/SetPptpServerCfg.
nvd
CVE-2022-43027CRITICALCVSS 9.8v16.03.13.112022-10-19
CVE-2022-43027 [CRITICAL] CWE-787 CVE-2022-43027: Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the f Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the firewallEn parameter at /goform/SetFirewallCfg.
nvd
CVE-2022-43026CRITICALCVSS 9.8v16.03.13.112022-10-19
CVE-2022-43026 [CRITICAL] CWE-787 CVE-2022-43026: Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the e Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCfg.
nvd
CVE-2022-43024CRITICALCVSS 9.8v16.03.13.112022-10-19
CVE-2022-43024 [CRITICAL] CWE-787 CVE-2022-43024: Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the l Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
nvd
CVE-2022-43029CRITICALCVSS 9.8v16.03.13.112022-10-19
CVE-2022-43029 [CRITICAL] CWE-787 CVE-2022-43029: Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the t Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the time parameter at /goform/SetSysTimeCfg.
nvd
CVE-2022-40942CRITICALCVSS 9.8v16.03.13.112022-09-28
CVE-2022-40942 [CRITICAL] CWE-787 CVE-2022-40942: Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time. Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time.
nvd