CVE-2025-65804

Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corruption and enable remote code execution (RCE).
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ax3_firmware:16.03.12.11:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ax3:-:*:*:*:*:*:*:*

History

11 Dec 2025, 00:03

Type Values Removed Values Added
References () https://river-brow-763.notion.site/Tenda-AX3-Buffer-Overflow-in-formSetIptv-2aaa595a7aef8072968edc528a2d95b1 - () https://river-brow-763.notion.site/Tenda-AX3-Buffer-Overflow-in-formSetIptv-2aaa595a7aef8072968edc528a2d95b1 - Exploit, Third Party Advisory
CPE cpe:2.3:h:tenda:ax3:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ax3_firmware:16.03.12.11:*:*:*:*:*:*:*
First Time Tenda
Tenda ax3
Tenda ax3 Firmware

08 Dec 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-08 18:15

Updated : 2025-12-11 00:03


NVD link : CVE-2025-65804

Mitre link : CVE-2025-65804

CVE.ORG link : CVE-2025-65804


JSON object : View

Products Affected

tenda

  • ax3
  • ax3_firmware
CWE
CWE-121

Stack-based Buffer Overflow